CWE-916

CWE-916 · 3 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-916, highest CVSS first.

  1. MEDIUM 4.9CVE-2026-92921public PoC

    admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can recover plaintext passwords through offline dictionary or brute-force attacks due to negligib…

    AI risk analysis on Exploit-DB.ai →

  2. LOW 3.7CVE-2026-105156public PoC

    A weakness has been identified in YzmCMS up to 7.6. Impacted is the function Password of the file /common/function/system.func.php of the component MD5 Handler. Executing a manipulation of the argument pass can lead to password hash with insufficient computati…

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-94206public PoC

    Use of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloak_ecto and danielberkompas cloak allows an attacker who holds the hashed values and the configured secret to brute-force low-entropy plaintexts much faster than co…

    AI risk analysis on Exploit-DB.ai →