CWE-317: Cleartext Storage of Sensitive Information in GUI
The product stores sensitive information in cleartext within the GUI.
Last updated
Overview
An attacker can often obtain data from a GUI, even if hidden, by using an API to directly access GUI objects such as windows and menus. Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.
Real-world CVEs
8 recorded CVEs are caused by CWE-317 (Cleartext Storage of Sensitive Information in GUI). The highest-severity and most recent are shown first. 3 new CWE-317 CVEs have been recorded so far in 2026.
- CVE-2025-14816
Information Disclosure, Tampering, and Denial-of-Service Vulnerabilities in GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, GENESIS, and MC Works64
Critical · CVSS 9.3 · EPSS 1th2026-04-08 - CVE-2026-27516
Binardat 10G08-0800GSM Network Switch Plaintext Password Exposure
High · CVSS 8.6 · EPSS 6th2026-02-24 - CVE-2022-29090