← Back
CWE-525

30 CVEs • Abstraction: Variant

Use of Web Browser Cache Containing Sensitive Information

The web application does not use an appropriate caching policy that specifies the extent to which each web page and associated form fields should be cached.

JSON object

Loading...

CVEs (30)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jul 17, 2026
Jul 17, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in appl...Show more
HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in application responses is stored in the local cache, then this may be retrieved by other users who have access to the same computer at a future time.Show less
-
-
Jul 22, 2026
Jun 2, 2026
5.9 MEDIUM· v4
5.7 MEDIUM· v3
N/A· v2
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applications stores sensitive information in the browser cache when an authenticated user modify specific conf...Show more
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applications stores sensitive information in the browser cache when an authenticated user modify specific configurations. This could allow an authenticated attacker to access sensitive data stored in the browser.Show less
-
-
Jun 17, 2026
Apr 24, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
@astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resources from _astro path with an incorrect/malformed if-match header returns a 500 error with a one year c...Show more
@astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resources from _astro path with an incorrect/malformed if-match header returns a 500 error with a one year cache lifetime instead of 412 in some cases. This has the effect that all subsequent requests to that file, regardless of if-match header will be served a 5xx error instead of the file until the cache expires. This vulnerability is fixed in 10.0.5.Show less
1Truesec
1Lapswebui
Jun 17, 2026
Mar 16, 2026
6.0 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin passwords.
1Ibm
1Devops Plan
Jun 17, 2026
Mar 3, 2026
N/A· v4
3.3 LOW· v3
N/A· v2
IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.
1Tenda
1F3 Firmware
Jun 17, 2026
Feb 23, 2026
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a sensitive information exposure vulnerability in the configuration download functionality. The configuration download response includes the router p...Show more
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a sensitive information exposure vulnerability in the configuration download functionality. The configuration download response includes the router password and administrative password in plaintext. The endpoint also omits appropriate Cache-Control directives, which can allow the response to be stored in client-side caches and recovered by other local users or processes with access to cached browser data.Show less
1Tenda
1W30e Firmware
Jun 17, 2026
Jan 26, 2026
4.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content without appropriate cache-control directives. As a result, browsers may store credential-bearing respo...Show more
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content without appropriate cache-control directives. As a result, browsers may store credential-bearing responses locally, exposing them to subsequent unauthorized access.Show less
1Hcltech
1Aion
Jun 17, 2026
Jan 19, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, potentially resulting in unauthorized access or information disclosure.
1Drupal
1Drupal
Jun 17, 2026
Nov 18, 2025
N/A· v4
3.7 LOW· v3
N/A· v2
Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: from 8.0.0 before 10.4...Show more
Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8, from 7.0 before 7.103.Show less
1Liferay
2Digital Experience Platform
Liferay Portal
Jun 17, 2026
Nov 1, 2025
4.6 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through up...Show more
The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions uses an incorrect cache-control header, which allows local users to obtain access to downloaded files via the browser's cache.Show less
1Hcltech
1Aion
Jun 17, 2026
Oct 10, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability  Cacheable SSL Page Found vulnerability has been identified in HCL AION.  Cached data may expose credentials, system identifiers, or internal file paths to attackers with access to the device or brows...Show more
A vulnerability  Cacheable SSL Page Found vulnerability has been identified in HCL AION.  Cached data may expose credentials, system identifiers, or internal file paths to attackers with access to the device or browser This issue affects AION: 2.0.Show less
1Ibm
1Openpages
Jun 17, 2026
Sep 15, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
IBM OpenPages 9.0 and 9.1 allows web page cache to be stored locally which can be read by another user on the system.
1Ibm
2Sterling B2b Integrator
Sterling File Gateway
Jun 17, 2026
Jun 18, 2025
N/A· v4
4.0 MEDIUM· v3
N/A· v2
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 could allow a local user to obtain sensitive information from a user’s web browser cache due to not using a su...Show more
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 could allow a local user to obtain sensitive information from a user’s web browser cache due to not using a suitable caching policy.Show less
-
-
Jun 17, 2026
Jun 4, 2025
7.7 HIGH· v4
N/A· v3
N/A· v2
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In Auth0 Next.js SDK versions 4.0.1 through 4.6.0, `__session` cookies set by auth0.middleware may be cached by CDNs due to...Show more
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In Auth0 Next.js SDK versions 4.0.1 through 4.6.0, `__session` cookies set by auth0.middleware may be cached by CDNs due to missing Cache-Control headers. Three preconditions must be met in order for someone to be affected by the vulnerability: Applications using the NextJS-Auth0 SDK, versions between 4.0.1 to 4.6.0, applications using CDN or edge caching that caches responses with the Set-Cookie header, and if the Cache-Control header is not properly set for sensitive responses. Users should upgrade auth0/nextjs-auth0 to v4.6.1 to receive a patch.Show less
1Ibm
2Cloud Pak For Security
Qradar Suite
Jun 17, 2026
Jun 3, 2025
N/A· v4
4.0 MEDIUM· v3
N/A· v2
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to be stored locally which can be read by another user on the system.
-
-
Jun 17, 2026
May 15, 2025
N/A· v4
3.9 LOW· v3
N/A· v2
Information Exposure vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 th...Show more
Information Exposure vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06.Show less
1Ibm
1Sterling Control Center
Jun 17, 2026
Apr 10, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
IBM Sterling Control Center 6.2.1, 6.3.1, and 6.4.0 allows web pages to be stored locally which can be read by another user on the system.
1Ibm
1Automation Decision Services
Jun 17, 2026
Jan 26, 2025
N/A· v4
6.2 MEDIUM· v3
N/A· v2
IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system.
1Ibm
2Devops Velocity
Urbancode Velocity
Jun 17, 2026
Jan 20, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system.
1Dpgaspar
1Flask Appbuilder
Jun 17, 2026
Sep 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using...Show more
Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer resources. Version 4.5.1 contains a patch for this issue. If upgrading is not possible, configure one's web server to send the specific HTTP headers for `/login` per the directions provided in the GitHub Security Advisory.Show less