CWE-204

Observable Response Discrepancy

Parent: CWE-203 - Observable Discrepancy

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

167 vulnerabilities with CWE-204
CVE-2026-2859 MEDIUM
Checkmk 2.4.0-2.4.0p22/2.3.0-2.3.0p42 - Info Disclosure
CVSS 4.3
CVE-2026-24097 MEDIUM
Checkmk 2.4.0-2.4.0p22, 2.3.0-2.3.0p42 - Info Disclosure
CVSS 4.3
CVE-2026-4045 LOW
projectsend r1945 - Info Disclosure
CVSS 3.7
CVE-2026-31901 MEDIUM
Parse Server <8.6.34/9.6.0-alpha.8 - Info Disclosure
CVSS 5.3
CVE-2026-31888 MEDIUM
Shopware <6.7.8.1/6.6.10.15 - Info Disclosure
CVSS 5.3
CVE-2026-28358 MEDIUM
NocoDB < 0.301.3 - User Enumeration via Password Reset Endpoint
CVSS 5.3
CVE-2026-28288 MEDIUM
Dify < 1.9.0 - Email Enumeration via Observable Response Discrepancy
CVSS 5.3
CVE-2026-25138 MEDIUM
Rucio <35.8.3/<38.5.4/<39.3.1 - Info Disclosure
CVSS 5.3
CVE-2026-27480 MEDIUM
Static Web Server 2.1.0-2.40.1 - Auth Bypass
CVSS 5.3
CVE-2026-26744 MEDIUM
FormaLMS < 4.1.18 - Unauthenticated User Enumeration via Password Recovery Response Discrepancy
CVSS 5.3
CVE-2026-25509 MEDIUM
Ci4-cms-erp Ci4ms < 0.28.5.0 - Information Disclosure
CVSS 5.3
CVE-2026-24664 MEDIUM
Open eClass Platform < 4.2 - Unauthenticated Username Enumeration via Login Response Analysis
CVSS 5.3
CVE-2026-24332 MEDIUM
Discord through 2026-01-16 - Information Disclosure via WebSocket API Response
CVSS 4.3
CVE-2026-23511 MEDIUM
ZITADEL <4.9.1, 3.4.6 - Info Disclosure
CVSS 5.3
CVE-2026-21484 MEDIUM
AnythingLLM <e287fab56089cf8fcea9ba579a3ecdeca0daa313 - Info Disclo...
CVSS 5.3
CVE-2025-67807 MEDIUM
Sage DPW <2021_06_000 - Info Disclosure
CVSS 4.7
CVE-2025-67806 LOW
Sage DPW <2021_06_000 - Info Disclosure
CVSS 3.7
CVE-2025-3716 MEDIUM
User enumeration in ESET Protect (on-prem)
CVE-2025-69243 MEDIUM
User enumeration in Raytha CMS
CVSS 5.3
CVE-2025-13460 MEDIUM
IBM Aspera Console Information Disclosure
CVSS 5.3
CVE-2025-12455 HIGH
OpenText Vertica 10.0-12.X - Password Brute Force
CVSS 7.5
CVE-2025-62512 MEDIUM
Piwigo 15.0.0-15.5.0 - Unauthenticated User Enumeration via Password Reset Endpoint
CVSS 5.3
CVE-2025-69413 MEDIUM
Gitea < 1.25.2 - Username Enumeration via API Authentication Response Discrepancy
CVSS 5.3
CVE-2025-67874 MEDIUM
ChurchCRM < 6.5.0 - Plaintext Password Exposure in HTTP Responses
CVSS 6.5
CVE-2025-62181 MEDIUM
Pega Platform <25.1.0 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 167