Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-204

MITRE ↗

CWE-204

2
CRITICAL
11
HIGH
140
MEDIUM
18
LOW
181 CVEs · Page 1/4
9.8
CVE-2018-25350

userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid u

9.1
CVE-2026-15747

Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH

8.6
CVE-2026-69519

Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a networ

7.5
CVE-2025-12455

Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing.   The vulnerability co

7.5
CVE-2026-33419

MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security T

7.5
CVE-2026-27462

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/inval

7.4
CVE-2026-60007

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA P

7.2
CVE-2026-4113

An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to

6.5
CVE-2026-34264

During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due t

5.3
CVE-2025-69413

In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username e

5.3
CVE-2026-21484

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti

5.3
CVE-2026-23511

ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has b

5.3
CVE-2026-24664

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,

5.3
CVE-2026-25509

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati

5.3
CVE-2019-25338

DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attac

5.3
CVE-2026-26744

A user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible v

5.3
CVE-2026-27480

Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. In versions 2.1.0 thro

5.3
CVE-2025-62512

Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the

5.3
CVE-2026-25138

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da

5.3
CVE-2026-28288

Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-exi

5.3
CVE-2026-28358

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password forgot endpoint return

5.3
CVE-2026-31888

Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/acc

5.3
CVE-2026-31901

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34

5.3
CVE-2025-13460

IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response disc

5.3
CVE-2025-69243

Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an atta

5.3
CVE-2026-30876

Chamilo LMS is a learning management system. Prior to version 1.11.36, Chamilo is vulnerable to user enumeration with va

5.3
CVE-2026-33688

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `o

5.3
CVE-2026-33323

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version

5.3
CVE-2026-40485

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/pu

5.3
CVE-2026-24468

OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campa

5.3
CVE-2026-20195

A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to e

5.3
CVE-2024-0391

The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker

5.3
CVE-2026-44306

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the f

5.3
CVE-2026-45620

WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or

5.3
CVE-2026-45294

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset

5.3
CVE-2026-53947

Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members sign

5.3
CVE-2026-61503

Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the

5.3
CVE-2024-23574

HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to

5.3
CVE-2026-42218

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login in

5.3
CVE-2026-14202

Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human

5.3
CVE-2026-55998

The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid

5.3
CVE-2026-72588

A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to d

5.3
CVE-2026-73306

Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the fa

5.3
CVE-2026-14672

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence

5.3
CVE-2026-75575

Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may

5.3
CVE-2026-81033

Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller

5.0
CVE-2026-34319

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are a

4.7
CVE-2025-67807

The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumer

4.3
CVE-2026-24332

Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actual

4.3
CVE-2026-24097

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows

Frequently Asked Questions

What is CWE-204?

CWE-204 (CWE-204) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-204?

There are 181 CVE records associated with CWE-204 in our database. Of these, 2 are critical severity, 11 are high severity, and 140 are medium severity.

How can I protect against CWE-204 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-204 using AI-powered security agents.

Detect CWE-204 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-204 vulnerabilities across your infrastructure.

Get Started