CWE-209: CWE-209

109
Total CVEs
12
Critical
20
High
6.1
Avg CVSS

Yearly Trend

2026
20
2025
43
2024
27
2023
10
2022
5

Top Affected Vendors

1 Ibm 23
2 Phpjabbers 5
3 Gitlab 4
4 Apache 4
5 Hcltech 3
6 Free5gc 3
7 Microsoft 2
8 Aptsys 2
9 Typo3 1
10 Codeigniter 1

All CWE-209 CVEs (109)

CVE-2025-66594
5.3

This vulnerability in Yokogawa's FAST/TOOLS software exposes detailed error messages that could reveal sensitive system information. Attackers could l...

Feb 9, 2026
CVE-2023-38017
5.3

IBM Cloud Pak System contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript into the web interface. ...

Feb 4, 2026
CVE-2023-38281
5.3

IBM Cloud Pak System fails to set the secure attribute on authorization tokens and session cookies, making them vulnerable to interception when transm...

Feb 4, 2026
CVE-2023-38010
5.3

IBM Cloud Pak System displays sensitive information in user messages that could aid attackers. This information disclosure vulnerability affects IBM C...

Feb 4, 2026
CVE-2025-11065
5.3

This vulnerability in the go-viper/mapstructure library allows information disclosure through detailed error messages that leak sensitive input values...

Jan 26, 2026
CVE-2025-52023
5.3

This vulnerability in gemscms.aptsys.com.sg's PHP backend allows unauthenticated remote attackers to trigger detailed error messages that disclose int...

Jan 23, 2026
CVE-2025-52022
5.3

This vulnerability allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and st...

Jan 23, 2026
CVE-2025-15526
5.3

The Fancy Product Designer WordPress plugin up to version 6.4.8 exposes server filesystem paths and stack traces in error messages through its PDF upl...

Jan 16, 2026
CVE-2025-9122
5.3

This vulnerability in Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework exposes detailed server stack traces throug...

Dec 15, 2025
CVE-2025-12365
5.3

This vulnerability involves error messages being exposed in HTTP headers, potentially leaking sensitive information about the system. It affects BLU-I...

Oct 27, 2025
CVE-2025-62397
5.3

This vulnerability allows attackers to enumerate valid course IDs on a router by observing inconsistent responses to invalid IDs. This information dis...

Oct 23, 2025
CVE-2025-54291
5.3

This vulnerability allows unauthenticated remote attackers to determine whether specific projects exist in Canonical LXD by observing different HTTP s...

Oct 2, 2025
CVE-2025-9229
5.3

An information disclosure vulnerability in MiR robot software allows unauthenticated attackers to access detailed error information including file pat...

Aug 20, 2025
CVE-2025-52619
5.3

HCL BigFix SaaS Authentication Service discloses sensitive version information through error messages under certain conditions. This information discl...

Aug 15, 2025
CVE-2025-54791
5.3

This vulnerability in OMERO.web's password reset functionality allows information disclosure about users when password reset errors occur. Attackers c...

Aug 13, 2025
CVE-2024-37524
5.3

IBM Analytics Content Hub versions 2.0-2.3 expose sensitive information through detailed error messages returned to browsers. This information disclos...

Jul 10, 2025
CVE-2025-20150
5.3

An unauthenticated remote attacker can enumerate valid LDAP usernames on vulnerable Cisco Nexus Dashboard systems by sending authentication requests. ...

Apr 16, 2025
CVE-2024-13537
5.3

The C9 Blocks WordPress plugin contains a publicly accessible file (composer-setup.php) that discloses the full server path when accessed. This affect...

Feb 21, 2025
CVE-2024-13538
5.3

The BigBuy Dropshipping Connector for WooCommerce WordPress plugin discloses the full server path through an accessible vendor file that triggers an e...

Feb 18, 2025
CVE-2024-13539
5.3

The AForms Eats WordPress plugin discloses full server path information through a publicly accessible vendor file. This information disclosure vulnera...

Feb 12, 2025
CVE-2024-35134
5.3

IBM Analytics Content Hub 2.0 discloses sensitive technical error information to remote attackers via browser responses. This information leakage coul...

Jan 25, 2025
CVE-2023-38714
5.3

IBM Cloud Pak System versions 2.3.3.0 through 2.3.3.7 iFix1 contain an information disclosure vulnerability that could expose sensitive system details...

Jan 25, 2025
CVE-2025-24552
5.3

This CVE describes an information disclosure vulnerability in the Paytium WordPress plugin where error messages reveal sensitive information like full...

Jan 24, 2025
CVE-2025-0053
5.3

SAP NetWeaver Application Server for ABAP and ABAP Platform contains an information disclosure vulnerability where unauthenticated attackers can acces...

Jan 14, 2025
CVE-2024-39725
5.3

This vulnerability in IBM Engineering Lifecycle Optimization - Engineering Insights allows remote attackers to obtain sensitive information through de...

Dec 25, 2024
CVE-2024-54366
5.3

This vulnerability in the Vimeography WordPress plugin exposes sensitive information through error messages, potentially revealing full server paths. ...

Dec 16, 2024
CVE-2024-52043
5.3

This vulnerability in HumHub allows attackers to enumerate valid usernames through error messages that leak sensitive information. All HumHub installa...

Nov 6, 2024
CVE-2024-50512
5.3

This vulnerability in the Posti Shipping WordPress plugin allows attackers to retrieve sensitive information through error messages. It affects all ve...

Oct 30, 2024
CVE-2024-44762
5.3

This vulnerability in Webmin Usermin v2.100 allows attackers to distinguish between valid and invalid user accounts through differences in error messa...

Oct 16, 2024
CVE-2024-45384
5.3

A padding oracle vulnerability in Apache Druid's optional druid-pac4j extension could allow attackers to manipulate session cookies. This affects Drui...

Sep 17, 2024
CVE-2024-45440
5.3

This vulnerability in Drupal 11.x-dev allows Full Path Disclosure when the hash_salt configuration points to a non-existent file. Attackers can exploi...

Aug 29, 2024
CVE-2024-35119
5.3

IBM InfoSphere Information Server 11.7 discloses sensitive technical information in error messages, potentially revealing system details that could ai...

Jun 30, 2024
CVE-2024-31844
5.3

This vulnerability in Italtel Embrace 1.6.4 allows unauthenticated attackers to trigger application errors that reveal sensitive server information li...

May 21, 2024
CVE-2024-45713
5.1

SolarWinds Kiwi CatTools can disclose sensitive information when a non-default troubleshooting setting is enabled. This affects administrators who hav...

Oct 17, 2024
CVE-2025-48562
5.0

This vulnerability in Android's RemotePrintDocument component allows local information disclosure through a logic error in writeContent. It affects An...

Sep 4, 2025
CVE-2025-36348
4.9

This vulnerability in IBM Sterling B2B Integrator and File Gateway exposes sensitive technical error messages to remote privileged attackers. Attacker...

Feb 17, 2026
CVE-2024-30141
4.7

HCL BigFix Compliance generates error messages that may leak sensitive information about the system environment, users, or associated data. This vulne...

Nov 7, 2024
CVE-2025-4166
4.5

CVE-2025-4166 allows sensitive information exposure in Vault server and audit logs when users submit malformed payloads during secret creation or upda...

May 2, 2025
CVE-2024-5435
4.5

This vulnerability in GitLab EE/CE allows attackers to retrieve user passwords stored in repository mirror configurations. It affects GitLab instances...

Sep 12, 2024
CVE-2024-12380
4.4

This vulnerability in GitLab EE/CE allows sensitive authentication information to be exposed through repository mirroring settings. Attackers could po...

Mar 13, 2025
CVE-2026-22646
4.3

This CVE describes an information disclosure vulnerability where error messages reveal internal system details like file paths, database errors, or so...

Jan 15, 2026
CVE-2025-13978
4.3

This vulnerability allows authenticated users to discover the names of private projects they shouldn't have access to through API requests. It affects...

Dec 11, 2025
CVE-2025-36437
4.3

This vulnerability in IBM Planning Analytics Local versions 2.1.0 through 2.1.15 allows attackers to obtain sensitive information about server archite...

Dec 9, 2025
CVE-2025-52671
4.3

This vulnerability allows non-admin users to view detailed debug information in SQL error messages, revealing software, PHP, and database version deta...

Nov 20, 2025
CVE-2025-54562
4.3

This vulnerability in Desktop Alert PingAlert's Application Server (versions 6.1.0.11 to 6.1.1.2) allows attackers to obtain technical information thr...

Nov 14, 2025
CVE-2025-59016
4.3

This vulnerability allows authenticated backend users in TYPO3 CMS to obtain sensitive file path information through error messages when file operatio...

Sep 9, 2025
CVE-2024-56342
4.3

IBM Verify Identity Access Digital Credentials 24.06 returns detailed technical error messages to browsers, potentially exposing sensitive system info...

Jun 6, 2025
CVE-2025-25025
4.3

IBM Security Guardium 12.0 discloses sensitive technical error information to remote attackers via browser responses. This information leakage could e...

May 28, 2025
CVE-2024-49798
4.3

IBM ApplinX 11.1 can expose sensitive technical error information to remote attackers through browser responses. This information disclosure vulnerabi...

Feb 6, 2025
CVE-2024-35111
4.3

IBM Control Center versions 6.2.1 and 6.3.1 expose detailed technical error messages to remote attackers, potentially revealing sensitive system infor...

Jan 25, 2025

About CWE-209 (CWE-209)

Our database tracks 109 CVEs classified as CWE-209, with 12 rated critical and 20 rated high severity. The average CVSS score for CWE-209 vulnerabilities is 6.1.

External reference: View CWE-209 on MITRE CWE →

Monitor CWE-209 Vulnerabilities

Get alerted when new CWE-209 CVEs affect your infrastructure.

Start Monitoring Free