CWE-538

Insertion of Sensitive Information into Externally-Accessible File or Directory

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.

72 vulnerabilities with CWE-538
CVE-2026-2817 MEDIUM
Spring Data Geode - Info Disclosure
CVSS 4.4
CVE-2020-37104 HIGH
ASTPP 4.0.1 - Info Disclosure
CVSS 7.5
CVE-2025-12059 CRITICAL
Logo j-Platform <3.34.8.9 - Info Disclosure
CVSS 9.8
CVE-2025-12699 MEDIUM
ZOLL ePCR IOS - SSRF
CVSS 5.5
CVE-2025-36058 MEDIUM
IBM Business Automation Workflow <25.0.0-24.0.1 - Info Disclosure
CVSS 5.5
CVE-2026-23838
Tandoor Recipes <26.05 - Info Disclosure
CVE-2025-68429 HIGH
NPM Storybook < 7.6.21 - Information Disclosure
CVSS 7.3
CVE-2025-61138 HIGH
Qlik Sense Enterprise <14.212.13 - Info Disclosure
CVSS 7.5
CVE-2021-4471
TG8 Firewall - Info Disclosure
CVE-2016-15056
Ubee EVW3226 <1.0.20 - Info Disclosure
CVE-2025-11891 MEDIUM
Shelf Planner <2.7.0 - Info Disclosure
CVSS 5.3
CVE-2025-46602 MEDIUM
Dell SupportAssist OS Recovery <5.5.15.0 - Info Disclosure
CVSS 4.4
CVE-2025-11079 MEDIUM
Campcodes Farm Management System 1.0 - Info Disclosure
CVSS 5.3
CVE-2025-58458 MEDIUM
Jenkins Git client Plugin <6.3.2 - Info Disclosure
CVSS 4.3
CVE-2025-57734 MEDIUM
JetBrains TeamCity <2025.07.1 - Info Disclosure
CVSS 4.3
CVE-2025-8452 MEDIUM
Brother - Info Disclosure
CVSS 4.3
CVE-2024-51977 MEDIUM
Multiple Brother devices authentication bypass via default administrator password generation
CVSS 5.3
CVE-2025-46820 HIGH
phpgt/Dom <4.1.8 - Info Disclosure
CVSS 7.1
CVE-2025-20665 MEDIUM
Google Android - Information Disclosure
CVSS 5.5
CVE-2025-31421 MEDIUM
Oblak Studio Srbtranslatin <3.2.0 - Info Disclosure
CVSS 5.8
CVE-2025-31558 MEDIUM
Greg TailPress <0.4.4 - Info Disclosure
CVSS 5.8
CVE-2025-31550 MEDIUM
thom4 WP-LESS <3 - Info Disclosure
CVSS 5.8
CVE-2025-25586 MEDIUM
R1bbit Yimioa < 2024-07-04 - Information Disclosure
CVSS 4.2
CVE-2025-27017 MEDIUM
Apache NiFi <2.3.0 - Info Disclosure
CVSS 6.5
CVE-2025-27150 MEDIUM
Tuleap <16.4.99.1740492866, <16.3-11 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 72