CWE-209— Generation of Error Message Containing Sensitive Information
535 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-209page 7 of 11
- CVE-2023-39264MEDIUMCVSS 4.3EG 4.32023-09-06
By default, stack traces for errors were enabled, which resulted in the exposure of internal traces on REST API endpoints to users. This vulnerability exists in Apache Superset versions up to and including 2.1.0.
- CVE-2023-40171CRITICALCVSS 9.1EG 9.12023-08-17
Dispatch is an open source security incident management tool. The server response includes the JWT Secret Key used for signing JWT tokens in error message when the `Dispatch Plugin - Basic Authentication Provider` plugin encounters an erro…
- CVE-2023-40457NONECVSS 0.0EG 0.02024-11-11
The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not on a directly connected network) to cause a denial of service (BGP session reset) because of BGP attribute error mishandling (for attribute 21…
- CVE-2023-40725MEDIUMCVSS 4.0EG 4.02023-09-12
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application returns inconsistent error messages in response to invalid user credentials during login session. This allows an attacker to enumerate …
- CVE-2023-40757CRITICALCVSS 9.8EG 9.82023-08-28
User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack w…
- CVE-2023-40758CRITICALCVSS 9.8EG 9.82023-08-28
User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with …
- CVE-2023-40759CRITICALCVSS 9.8EG 9.82023-08-28
User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force at…
- CVE-2023-40760CRITICALCVSS 9.8EG 9.82023-08-28
User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack …
- CVE-2023-40761CRITICALCVSS 9.8EG 9.82023-08-28
User enumeration is found in PHPJabbers Yacht Listing Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack w…
- CVE-2023-40762CRITICALCVSS 9.8EG 9.82023-08-28
User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack wit…
- CVE-2023-40763CRITICALCVSS 9.8EG 9.82023-08-28
User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack wi…
- CVE-2023-40764CRITICALCVSS 9.8EG 9.82023-08-28
User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack wit…
- CVE-2023-40765CRITICALCVSS 9.8EG 9.82023-08-28
User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack…
- CVE-2023-40766CRITICALCVSS 9.8EG 9.82023-08-28
User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force atta…
- CVE-2023-40767CRITICALCVSS 9.8EG 9.82023-08-28
User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attac…
- CVE-2023-41027HIGHCVSS 8.0EG 8.02023-09-22
Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administrative account via requests to the vulne…
- CVE-2023-41365MEDIUMCVSS 4.3EG 4.32023-10-10
SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure. After successful exploitation, an attack…
- CVE-2023-42013MEDIUMCVSS 5.3EG 5.32023-12-20
IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This informati…
- CVE-2023-42475MEDIUMCVSS 4.3EG 4.32023-10-10
The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker to read server files with minimal impact on confidentiality.
- CVE-2023-43021MEDIUMCVSS 5.3EG 5.32023-12-01
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.…
- CVE-2023-4457MEDIUMCVSS 5.5EG 5.52023-10-16
Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability. The plugin did not properly sanitiz…
- CVE-2023-45701MEDIUMCVSS 4.3EG 4.32023-12-28
HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
- CVE-2023-46240HIGHCVSS 7.5EG 7.52023-10-31
CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a detailed error report is displayed even if in the production environment. As a result, confidential information may be l…
- CVE-2023-47152MEDIUMCVSS 5.9EG 5.92024-01-22
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure cryptographic algorithm and to information disclosure in stack trace under exceptional conditions.
- CVE-2023-47636MEDIUMCVSS 5.3EG 5.32023-11-15
The Pimcore Admin Classic Bundle provides a Backend UI for Pimcore. Full Path Disclosure (FPD) vulnerabilities enable the attacker to see the path to the webroot/file. e.g.: /home/omg/htdocs/file/. Certain vulnerabilities, such as using th…
- CVE-2023-47639MEDIUMCVSS 5.3EG 5.32025-04-03
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. From 3.2.0 until 3.2.4, exception messages, that are not HTTP exceptions, are visible in the JSON error response. This vulnerability is fixed in 3.2.5.
- CVE-2023-47703MEDIUMCVSS 5.3EG 5.32023-12-20
IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against th…
- CVE-2023-47728MEDIUMCVSS 6.5EG 4.92024-08-16
IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the reques…
- CVE-2023-48393MEDIUMCVSS 4.3EG 4.32023-12-15
Kaifa Technology WebITR is an online attendance system. A remote attacker with regular user privilege can obtain partial sensitive system information from error message.
- CVE-2023-49080LOWCVSS 3.5EG 3.52023-12-04
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. Unhandled errors in API requests coming from an authenticated user includ…
- CVE-2023-49107MEDIUMCVSS 5.3EG 5.32024-01-16
Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before 8.8.5-04.
- CVE-2023-49878MEDIUMCVSS 4.3EG 4.32023-12-13
IBM System Storage Virtualization Engine TS7700 3957-VEC, 3948-VED and 3957-VEC could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be us…
- CVE-2023-50348LOWCVSS 3.1EG 3.12024-01-03
HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error messages that can provide an attacker with insight into the application, system, etc.
- CVE-2023-50355LOWCVSS 3.6EG 3.62024-10-23
HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack.
- CVE-2023-5089MEDIUMCVSS 5.3EG 5.32023-10-16
The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page function…
- CVE-2023-50953MEDIUMCVSS 5.4EG 5.42024-06-30
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system. IBM X-Force I…
- CVE-2023-5177MEDIUMCVSS 5.3EG 5.32023-10-16
The Vrm 360 3D Model Viewer WordPress plugin through 1.2.1 exposes the full path of a file when putting in a non-existent file in a parameter of the shortcode.
- CVE-2023-5514MEDIUMCVSS 5.3EG 5.32023-11-01
The response messages received from the eSOMS report generation using certain parameter queries with full file path can be abused for enumerating the local file system structure.
- CVE-2023-5617MEDIUMCVSS 5.3EG 5.32024-02-28
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error is encountered.
- CVE-2023-6839MEDIUMCVSS 5.3EG 5.32023-12-15
Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP response.
- CVE-2023-6944MEDIUMCVSS 5.7EG 5.72024-01-04
A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display …
- CVE-2024-11129MEDIUMCVSS 6.3EG 6.32025-04-10
An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. This allows attackers to perform targeted searches with sensitive keywords to get the count of issues …
- CVE-2024-11625HIGHCVSS 7.7EG 7.72025-01-07
Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.…
- CVE-2024-12380MEDIUMCVSS 4.4EG 4.42025-03-13
An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository mirroring sett…
- CVE-2024-13535MEDIUMCVSS 5.3EG 5.32025-02-18
The Actionwear products sync plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.3.2. This is due the composer-setup.php file being publicly accessible with 'display_errors' set to true. This …
- CVE-2024-13536MEDIUMCVSS 5.3EG 5.32025-01-21
The 1003 Mortgage Application plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.87. This is due the /inc/class/fnm/export.php file being publicly accessible with error logging enabled. This …
- CVE-2024-13537MEDIUMCVSS 5.3EG 5.32025-02-21
The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. This is due the plugin containing a publicly accessible composer-setup.php file with error display enabled. This makes it…
- CVE-2024-13538MEDIUMCVSS 5.3EG 5.32025-02-18
The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.0. This is due the /vendor/cocur/slugify/bin/generate-default.php file being directly ac…
- CVE-2024-13539MEDIUMCVSS 5.3EG 5.32025-02-12
The AForms Eats plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.3.1. This is due the /vendor/aura/payload-interface/phpunit.php file being publicly accessible and displaying error messages…
- CVE-2024-13540MEDIUMCVSS 5.3EG 5.32025-02-18
The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.5.1. This is due the /inc/bycwooodt_get_all_orders.php file being p…
Map vulnerabilities like CWE-209 to your infrastructure
EchelonGraph correlates every CVE — across CWE-209 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →