CWE-538Base

Insertion of Sensitive Information into Externally-Accessible File or Directory

Draft in the CWE catalog · 83 CVEs mapped

83
CVEs mapped
6.3
Median CVSS
What it is

The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.

Recent examples
none
CVE-2026-67361

CVE-2026-67361 - UNKNOWN Severity Vulnerability

Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests from unauthenticated visitors with no CSRF token. Compounding this, the installer manifest omitted the upload and invoices directories, causing fresh installs to deploy those directories without .htaccess/web.config protection, making uploaded files directly web-accessible.

no explanation yet
0%
epss
5.3cvss
CVE-2026-19229

CVE-2026-19229 - MEDIUM Severity Vulnerability

A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of the component Dreamweaver Metadata Files. Executing a manipulation can lead to file and directory information exposure. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

MEDIUMno explanation yet
0%
epss
5.3cvss
CVE-2026-12762

CVE-2026-12762 - MEDIUM Severity Vulnerability

IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-538
Abstraction
Base
Structure
Simple
Status
Draft