The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
Volume of CVEs assigned to CWE-204 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
167 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41697MEDIUM A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive informati | Dec 22, 2022 | 5.3 | 40 | NO | YES |
CVE-2026-15747CRITICAL Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle.
_csrf_token generates and caches one t | Jul 14, 2026 | 9.1 | 39 | NO | NO |
CVE-2018-25350CRITICAL userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameChe | May 23, 2026 | 9.8 | 37 | NO | NO |
CVE-2025-62512MEDIUM Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the password reset functionality in Piwigo allows an unauthentic | Feb 24, 2026 | 5.3 | 31 | NO | YES |
CVE-2025-12455HIGH Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing.
The vulnerability could lead to Password Brute Forcing in Vertica management con | Mar 13, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-28358MEDIUM NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password forgot endpoint returned different responses for registered and unregistered email | Mar 2, 2026 | 5.3 | 30 | NO | YES |
CVE-2026-28288MEDIUM Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate ema | Feb 27, 2026 | 5.3 | 30 | NO | YES |
CVE-2026-21484MEDIUM AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to commit e287fab56089cf8fcea9ba579a3ecdeca0daa313 | Jan 3, 2026 | 5.3 | 30 | NO | YES |
CVE-2026-61503MEDIUM Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the submitted username exists. A remote unauthenticated attacker | Jul 13, 2026 | 5.3 | 28 | NO | NO |
CVE-2026-54445MEDIUM vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not ide | Jun 17, 2026 | 6.9 | 28 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.