CWE-256— Plaintext Storage of a Password
The product stores a password in plaintext within resources such as memory or files.— MITRE CWE catalog
261 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-256page 6 of 6
- CVE-2026-46513HIGHCVSS 7.4EG 7.42026-07-16
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by Tools/CreateApiToken.php:33-36 as raw bin2hex(random_bytes(32)) strings in oc_api_tokens, and Frogman.class.php:78 authe…
- CVE-2026-50268LOWCVSS 1.9EG 1.92026-06-17
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 through 4.1.0, configuring `encrypt:rsa:algorithm=OAEP` does not enable…
- CVE-2026-50641HIGHCVSS 7.1EG 7.12026-07-29
Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in version 6.8.0.0, users were also requested to change their password on the first login.
- CVE-2026-55164MEDIUMCVSS 4.9EG 4.92026-06-25
Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replacement password directly to users.password, while lemur/users/models.py registered User.hash_password only for the before_insert event. Beca…
- CVE-2026-55765HIGHCVSS 8.5EG 8.52026-08-20
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUs…
- CVE-2026-57302MEDIUMCVSS 4.3EG 4.32026-06-24
Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Extended Read permission or access to the Jenkins controller file system.
- CVE-2026-61886MEDIUMCVSS 6.5EG 6.52026-07-24
Weintek cMT3092X HMI stores user account passwords in plaintext.
- CVE-2026-6500MEDIUMCVSS 4.8EG 4.82026-05-04
Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. This issue affects OpenConcerto: 1.7.5.
- CVE-2026-6597LOWCVSS 2.7EG 2.72026-04-20
A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py of the component Flow Using API. This manipulation causes un…
- CVE-2026-82453HIGHCVSS 7.5EG 7.52026-08-29
rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.
- CVE-2026-82783MEDIUMCVSS 4.2EG 4.22026-09-14
Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product may obtain credentials.
Map vulnerabilities like CWE-256 to your infrastructure
EchelonGraph correlates every CVE — across CWE-256 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →