CWE-525: Use of Web Browser Cache Containing Sensitive Information
The web application does not use an appropriate caching policy that specifies the extent to which each web page and associated form fields should be cached.
Last updated
Overview
CWE-525 (Use of Web Browser Cache Containing Sensitive Information) is a variant-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
29 recorded CVEs are caused by CWE-525 (Use of Web Browser Cache Containing Sensitive Information). The highest-severity and most recent are shown first. 7 new CWE-525 CVEs have been recorded so far in 2026 (11 in 2025).
- CVE-2025-48947
NextJS-Auth0 SDK Vulnerable to CDN Caching of Session Cookies
High · CVSS 7.7 · EPSS 52th2025-06-04 - CVE-2026-27514
Tenda F3 Plaintext Credential Exposure in Configuration Download
High · CVSS 7.1 · EPSS 15th2026-02-23 - CVE-2025-36364
IBM DevOps Plan REST APIs are vulnerable to exposure of sensitive data through request query parameters.