CWE-256

High likelihood

Plaintext Storage of a Password

Parent: CWE-522 - Insufficiently Protected Credentials

The product stores a password in plaintext within resources such as memory or files.

215 vulnerabilities with CWE-256
CVE-2026-50641 HIGH
Plaintext password storage in Streamsoft Business Intelligence
CVE-2026-41874 MEDIUM
Hard-coded admin credentials in Quick.Cart
CVE-2026-61886 MEDIUM
Weintek cMT3092X Plaintext Storage of a Password
CVSS 6.5
CVE-2026-40430 HIGH
Plaintext Storage of a Password in Panduit IntraVUE by Pronetiqs
CVSS 7.5
CVE-2026-44187 LOW
Ansible-lightspeed: ansible lightspeed extension for visual studio code: information disclosure of google gemini api key
CVSS 3.3
CVE-2026-46513 HIGH
Frogman: API tokens stored in plaintext
CVSS 7.4
CVE-2026-14867 MEDIUM
arcinfo PcVue - Insecure Password Storage in User Directory
CVSS 5.5
CVE-2026-57302 MEDIUM
Jenkins FitNesse Plugin - Plaintext Storage of a Password
CVSS 4.3
CVE-2026-50268 LOW
Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding
CVSS 1.9
CVE-2026-36174 MEDIUM
GNCC GP5 7.1.76 - Sensitive Information Exposure via Serial UART Interface
CVSS 4.6
CVE-2026-42151 HIGH
Prometheus Azure AD remote write OAuth client secret exposed via config API
CVSS 7.5
CVE-2026-6500 MEDIUM
OpenConcerto 1.7.5 - Info Disclosure
CVE-2026-6597 LOW
langflow-ai langflow Flow Using API core.py has_api_terms credentials storage
CVSS 2.7
CVE-2026-35556 HIGH
Plaintext storage of a password in OpenPLC_V3
CVSS 7.5
CVE-2026-33216 HIGH
NATS has MQTT plaintext password disclosure
CVSS 8.6
CVE-2026-31850 MEDIUM
Plaintext storage of credentials in configuration backup in Nexxt Nebula 300+
CVSS 4.9
CVE-2026-4251 LOW
CityData CityChat ai.citydata.citychat credentials.json credentials storage
CVSS 2.5
CVE-2026-4250 LOW
Albert Sağlık Hizmetleri ve Ticaret Albert Health Google Cloud Service Account Key service-account.json credentials storage
CVSS 2.5
CVE-2026-4243 LOW
La Nacion App app.lanacion.activity BuildConfig.java credentials storage
CVSS 2.5
CVE-2026-4242 LOW
BabyChakra Pregnancy & Parenting App app.babychakra.babychakra Configuration.java credentials storage
CVSS 2.5
CVE-2026-4217 LOW
XREAL Nebula App ai.nreal.nebula.universal CloudStoragePlugin.java key management
CVSS 2.5
CVE-2026-22285 MEDIUM
Dell Device Management Agent < 26.02 - Plaintext Storage of Password
CVSS 4.4
CVE-2026-28360 MEDIUM
NocoDB < 0.301.3 - Plaintext Password Storage in Shared View
CVSS 5.3
CVE-2026-21660 CRITICAL
Frick Controls Quantum HD <10.22 - Info Disclosure
CVSS 9.8
CVE-2026-23797 MEDIUM
Quick.Cart 6.7 - Plaintext Password Storage
CVSS 4.9
Details
Vulnerabilities 215
Exploit Likelihood High