CWE-798


Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.


We have discovered 2,057 live websites that are affected by CWE-798.

Contact us to get more info









CVEs

  • Count - 5



Website Distribution by Country

Number of websites using CWE-798
United States603 websites



Germany185 websites
GB106 websites
Russia104 websites
France101 websites
Netherlands99 websites
Poland64 websites
Australia55 websites
Japan55 websites
Canada55 websites

Website Distribution by TLD

Number of websites using CWE-798
.com795 websites
.org103 websites
.de103 websites
.ru92 websites
.co.uk69 websites
.nl60 websites
.com.au58 websites
.fr52 websites
.eu49 websites
.pl48 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-798
DiscoveredCVEDescriptionWebsites
Sep, 2025CVE-2025-58659 WordPress Helpie FAQ Plugin <= 1.39 - Sensitive Data Exposure Vulnerability1,988
Sep, 2025CVE-2025-8570 BeyondCart Connector <= 2.1.0 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation via determine_current_user Filter1
Sep, 2025CVE-2025-55739 api: Shared OAuth Signing Key Between Different Instances2
Aug, 2024CVE-2024-28987 SolarWinds Web Help Desk Hardcoded Credential Vulnerability34
May, 2020CVE-2020-5248 Public GLPIKEY can be used to decrypt any data in GLPI32
List of the most common CVEs that are part of CWE-798
DiscoveredCVEDescriptionWebsites
Sep, 2025CVE-2025-58659 WordPress Helpie FAQ Plugin <= 1.39 - Sensitive Data Exposure Vulnerability1,988
Aug, 2024CVE-2024-28987 SolarWinds Web Help Desk Hardcoded Credential Vulnerability34
May, 2020CVE-2020-5248 Public GLPIKEY can be used to decrypt any data in GLPI32
Sep, 2025CVE-2025-55739 api: Shared OAuth Signing Key Between Different Instances2
Sep, 2025CVE-2025-8570 BeyondCart Connector <= 2.1.0 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation via determine_current_user Filter1

Websites affected by CWE-798

Top websites that are affected by CWE-798. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com United States**,***
*************.com United States**,***
*******************.com United States**,***
**********.com Iceland***,***
*******.nl United States***,***
*******.com United States***,***
********.com Lithuania***,***
*****.it Italy***,***
***.dk Denmark***,***
***********.jp Japan***,***
See full domain list