← Back
CWE-256

220 CVEs • Abstraction: Base • Likelihood of Exploit: High

Plaintext Storage of a Password

Storing a password in plaintext may result in a system compromise.

JSON object

Loading...

CVEs (220)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ormazabal
2Ekorccp Firmware
Ekorrci Firmware
Jun 17, 2026
Sep 20, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The web application stores credentials in clear text in the "admin.xml" file, which can be accessed without logging into the website, which could allow an attacker to obtain credentials related to all users, including ad...Show more
The web application stores credentials in clear text in the "admin.xml" file, which can be accessed without logging into the website, which could allow an attacker to obtain credentials related to all users, including admin users, in clear text, and use them to subsequently execute malicious actions.Show less
1Socomec
1Modulys Gp Firmware
Jun 17, 2026
Sep 18, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions i...Show more
The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application. Show less
1Redhat
1Openstack Platform
Jun 17, 2026
Sep 15, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem.
1Didiglobal
1Knowsearch
Jun 17, 2026
Sep 15, 2023
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in didi KnowSearch 0.3.2/0.3.1.2. It has been rated as problematic. This issue affects some unknown processing of the file /api/es/admin/v3/security/user/1. The manipulation leads to unprotected...Show more
A vulnerability was found in didi KnowSearch 0.3.2/0.3.1.2. It has been rated as problematic. This issue affects some unknown processing of the file /api/es/admin/v3/security/user/1. The manipulation leads to unprotected storage of credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239795.Show less
1Skyhighsecurity
1Secure Web Gateway
Jun 17, 2026
Sep 13, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and controlled release 12.x prior to 12.2.1, allows some authentication information s...Show more
A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and controlled release 12.x prior to 12.2.1, allows some authentication information stored in configuration files to be extracted through SWG REST API. This was possible due to SWG storing the password in plain text in some configuration files. Show less
1Redhat
1Keycloak
Jun 17, 2026
Sep 12, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "password" and "password-confirm" field from the form will occur as regula...Show more
A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "password" and "password-confirm" field from the form will occur as regular user attributes. All users and clients with proper rights and roles are able to read users attributes, allowing a malicious user with minimal access to retrieve the users passwords in clear text, jeopardizing their environment.Show less
1Softneta
1Meddream Pacs
Jun 17, 2026
Sep 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
​Softneta MedDream PACS stores usernames and passwords in plaintext. The plaintext storage could be abused by attackers to leak legitimate user’s credentials.
1Infodrom
1E Invoice Approval System
Jun 17, 2026
Jul 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Plaintext Storage of a Password vulnerability in Infodrom Software E-Invoice Approval System allows Read Sensitive Strings Within an Executable. This issue affects E-Invoice Approval System: before v.20230701.
1Piigab
1M Bus 900s Firmware
Jun 17, 2026
Jul 7, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
PiiGAB M-Bus stores credentials in a plaintext file, which could allow a low-level user to gain admin credentials.
1Ovarro
5Tbox Lt2 Firmware
Tbox Ms Cpu32 S2 FirmwareTbox Ms Cpu32 Firmware+2 more
Jun 17, 2026
Jul 3, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
​All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, including sensitive informat...Show more
​All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, including sensitive information associated with document, such as password. The attacker could then obtain the plaintext password by using a memory viewer. Show less
1Fortinet
1Fortisiem
Jun 17, 2026
Jun 13, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 a...Show more
A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB content to impersonate any admin user on the device GUI.Show less
1Jenkins
1Code Dx
Jun 17, 2026
May 16, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins Code Dx Plugin 3.1.0 and earlier does not mask Code Dx server API keys displayed on the configuration form, increasing the potential for attackers to observe and capture them.
1Jenkins
1Code Dx
Jun 17, 2026
May 16, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins Code Dx Plugin 3.1.0 and earlier stores Code Dx server API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the...Show more
Jenkins Code Dx Plugin 3.1.0 and earlier stores Code Dx server API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.Show less
1Secomea
1Gatemanager
Jun 17, 2026
Apr 19, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked.
1Mitsubishielectric
38Fx5 Enet/ip Firmware
Fx5 Enet FirmwareFx5s 30mr/es Firmware+35 more
Jun 17, 2026
Mar 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext...Show more
Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP server or Web server.Show less
1Snapav
1Wattbox Wb 300 Ip 3 Firmware
Jun 17, 2026
Jan 30, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior store passwords in a plaintext file when the device configuration is exported via Save/Restore–>Backup Settings, which could be read by any user accessing the fi...Show more
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior store passwords in a plaintext file when the device configuration is exported via Save/Restore–>Backup Settings, which could be read by any user accessing the file.   Show less
1Ibm
1Security Verify Governance
Jun 17, 2026
Dec 22, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read by a remote authenticated user. IBM X-Force ID: 225009.
1Ibm
1Maximo Application Suite
Jun 17, 2026
Nov 28, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407.
1Siemens
1Qms Automotive
Jun 17, 2026
Nov 8, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could al...Show more
A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to gain access to credentials and impersonate other users.Show less
2Pulpproject
Redhat
4Ansible Automation Platform
Pulp AnsibleSatellite+1 more
Jun 17, 2026
Oct 25, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.