CWE · MITRE source
CWE-549Missing Password Field Masking
The product does not mask passwords during entry, increasing the potential for attackers to observe and capture passwords.
Last updated: 20 August 2026 13:14 UTC
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (1)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
IA-6 | Authentication Feedback | IA | Obscuring feedback includes masking password input (e.g., asterisks), which addresses the weakness of missing password field masking. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2022-22550 UPD | 5.0 | 6.7 | 0.0023 | 2022-04-12 |
CVE-2023-1763 UPD | 5.0 | 6.5 | 0.0028 | 2023-05-17 |
CVE-2025-42904 UPD | 5.0 | 6.5 | 0.0032 | 2025-12-09 |
CVE-2023-2062 UPD | 4.8 | 6.2 | 0.0033 | 2023-06-02 |
CVE-2025-31727 UPD | 4.4 | 5.5 | 0.0028 | 2025-04-02 |
CVE-2025-31728 UPD | 4.4 | 5.5 | 0.0028 | 2025-04-02 |
CVE-2022-20914 UPD | 4.2 | 4.9 | 0.0092 | 2022-08-10 |
CVE-2023-49106 UPD | 3.8 | 4.6 | 0.0044 | 2024-01-16 |
CVE-2022-1342 UPD | 3.7 | 4.6 | 0.0038 | 2022-06-15 |
CVE-2025-4526 UPD | 3.6 | 4.3 | 0.0029 | 2025-05-11 |
CVE-2026-3314 UPD | 3.6 | 4.6 | 0.0018 | 2026-05-26 |
CVE-2025-64170 UPD | 3.0 | 3.8 | 0.0014 | 2025-11-12 |
CVE-2025-30197 UPD | 2.8 | 3.1 | 0.0027 | 2025-03-19 |
CVE-2024-10122 UPD | 2.6 | 2.7 | 0.0049 | 2024-10-18 |
CVE-2025-0148 UPD | 2.4 | 2.6 | 0.0017 | 2025-02-03 |