CWE-916
CWE-916 · 3 records · 3 with a public proof-of-concept
Records the NVD classes under CWE-916, highest CVSS first.
- MEDIUM 4.9CVE-2026-92921public PoC
admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can recover plaintext passwords through offline dictionary or brute-force attacks due to negligib…
- LOW 3.7CVE-2026-105156public PoC
A weakness has been identified in YzmCMS up to 7.6. Impacted is the function Password of the file /common/function/system.func.php of the component MD5 Handler. Executing a manipulation of the argument pass can lead to password hash with insufficient computati…
- UNSCOREDCVE-2026-94206public PoC
Use of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloak_ecto and danielberkompas cloak allows an attacker who holds the hashed values and the configured secret to brute-force low-entropy plaintexts much faster than co…