← Back
CWE-359

203 CVEs • Abstraction: Base

Exposure of Private Personal Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

JSON object

Loading...

CVEs (203)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Prestashop
1Prestashop
Jun 17, 2026
Sep 8, 2025
N/A· v4
3.7 LOW· v3
N/A· v2
An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.
-
-
Jun 17, 2026
Aug 19, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A low-privileged remote attacker can obtain the username of another registered Sunny Portal user by entering that user's email address.
1Microsoft
1Azure App Service On Azure Stack
Jun 17, 2026
Aug 12, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.
1Xwiki
1Xwiki
Jun 17, 2026
Aug 6, 2025
8.7 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 1.1 through 16.4.6, 16.5.0-rc-1 through 16.10.4...Show more
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 1.1 through 16.4.6, 16.5.0-rc-1 through 16.10.4 and 17.0.0-rc-1 through 17.1.0, the XML export of a page in XWiki that can be triggered by any user with view rights on a page by appending ?xpage=xml to the URL includes password and email properties stored on a document that aren't named password or email. This is fixed in versions 16.4.7, 16.10.5 and 17.2.0-rc-1. To work around this issue, the file templates/xml.vm in the deployed WAR can be deleted if the XML isn't needed. There isn't any feature in XWiki itself that depends on the XML export.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Aug 6, 2025
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 9.8-rc-1 through 16.4.6, 16.5.0-rc-1 through 16...Show more
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 9.8-rc-1 through 16.4.6, 16.5.0-rc-1 through 16.10.4, and 17.0.0-rc-1 through 17.1.0, any user with editing rights can create an XClass with a database list property that references a password property. When adding an object of that XClass, the content of that password property is displayed. In practice, with a standard rights setup, this means that any user with an account on the wiki can access password hashes of all users, and possibly other password properties (with hashed or plain storage) that are on pages that the user can view. This issue is fixed in versions 16.4.7, 16.10.5 and 17.2.0-rc-1.Show less
1Apple
1Macos
Jun 17, 2026
Jul 30, 2025
N/A· v4
4.6 MEDIUM· v3
N/A· v2
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker with physical access to a locked device may be...Show more
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker with physical access to a locked device may be able to view sensitive user information.Show less
1Apple
7Ipados
Iphone OsMacos+4 more
Jun 17, 2026
Jul 30, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web cont...Show more
This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose sensitive user information.Show less
1Apple
2Ipados
Iphone Os
Jun 17, 2026
Jul 30, 2025
N/A· v4
4.0 MEDIUM· v3
N/A· v2
The issue was addressed by adding additional logic. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Privacy Indicators for microphone or camera access may not be correctly displayed.
1Apple
2Ipados
Iphone Os
Jun 17, 2026
Jul 30, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
This issue was addressed through improved state management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Remote content may be loaded even when the 'Load Remote Images' setting is turned off.
-
-
Jun 17, 2026
Jul 10, 2025
8.7 HIGH· v4
N/A· v3
N/A· v2
The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with various formats and details. Several #dpl parameters can leak usernames that have been hidden using revisi...Show more
The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with various formats and details. Several #dpl parameters can leak usernames that have been hidden using revision deletion, suppression, or the hideuser block flag. The vulnerability is fixed in 3.6.4.Show less
1Dokploy
1Dokploy
Jun 17, 2026
Jul 7, 2025
1.3 LOW· v4
4.3 MEDIUM· v3
N/A· v2
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated low-privileged account can retrieve detailed profile information about...Show more
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated low-privileged account can retrieve detailed profile information about another users in the same organization by directly invoking user.one. The response discloses personally-identifiable information (PII) such as e-mail address, role, two-factor status, organization ID, and various account flags. The fix will be available in the v0.23.7.Show less
1Redhat
1Advanced Cluster Management For Kubernetes
Jun 17, 2026
Jul 2, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed clus...Show more
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only be accessible to authorized users and may result in the loss of confidentiality of administrative information, which could be leaked to unauthorized actors.Show less
1Microsoft
1Dynamics 365
Jun 17, 2026
Jun 20, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network.
1Weblate
1Weblate
Jun 17, 2026
Jun 16, 2025
2.1 LOW· v4
5.3 MEDIUM· v3
N/A· v2
Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam fil...Show more
Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. This issue has been patched in version 5.12.Show less
1Devolutions
1Remote Desktop Manager
Jun 17, 2026
May 29, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows an authenticated user to gain unauthorized access to private personal informatio...Show more
Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows an authenticated user to gain unauthorized access to private personal information. Under specific circumstances, entries may be unintentionally moved from user vaults to shared vaults when edited by their owners, making them accessible to other users. This issue affects the following versions : * Remote Desktop Manager Windows 2025.1.34.0 and earlier * Remote Desktop Manager macOS 2025.1.16.3 and earlier * Remote Desktop Manager Android 2025.1.3.3 and earlier * Remote Desktop Manager iOS 2025.1.6.0 and earlierShow less
-
-
Jun 17, 2026
May 22, 2025
6.9 MEDIUM· v4
4.9 MEDIUM· v3
N/A· v2
Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
1Gitlab
1Gitlab
Jun 17, 2026
May 22, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that...Show more
An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured.Show less
1Hcltech
1Domino Leap
Jun 17, 2026
Apr 30, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
1Hcltech
1Hcl Leap
Jun 17, 2026
Apr 24, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
1Zabbix
1Zabbix
Jun 17, 2026
Apr 2, 2025
2.1 LOW· v4
3.5 LOW· v3
N/A· v2
Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.