Cyber Posture

CWE · MITRE source

CWE-256Plaintext Storage of a Password

Abstraction: Base · CVEs in our corpus: 201

The product stores a password in plaintext within resources such as memory or files.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (1)AI

Control Title Family Why it addresses this CWE
SC-28Protection of Information at RestSCProtection of passwords and credentials at rest forces encryption or equivalent controls instead of plaintext storage.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2017-167142.19.80.02332018-09-06
CVE-2017-79132.09.80.00222017-05-29
CVE-2018-75102.09.80.00252018-06-06
CVE-2018-88512.09.80.00222018-07-24
CVE-2020-69612.010.00.00192020-01-24
CVE-2024-234862.09.80.00482024-04-15
CVE-2024-360812.09.80.00142024-05-19
CVE-2024-333752.09.80.00162024-06-14
CVE-2024-59602.09.80.00252024-09-18
CVE-2025-276562.09.80.00132025-03-05
CVE-2025-276622.09.80.00392025-03-05
CVE-2025-58932.09.80.00592025-06-09
CVE-2025-65602.09.80.00592025-06-24
CVE-2025-65612.09.80.00592025-06-26
CVE-2026-216602.09.80.00052026-02-27
CVE-2024-550262.09.80.00092026-03-03
CVE-2024-261651.98.80.02462024-03-12
CVE-2025-151131.99.30.00032025-12-30
CVE-2020-53741.88.80.00402020-07-14
CVE-2020-53151.88.80.00042021-07-19
CVE-2022-363081.89.10.00262022-08-16
CVE-2023-49181.88.80.00082023-09-12
CVE-2024-36221.88.80.00152024-04-25
CVE-2024-61181.89.10.00152024-08-05
CVE-2023-416101.88.80.00112024-09-18