{"api_version":"1","generated_at":"2026-07-23T12:37:26+00:00","cve":"CVE-2026-16213","urls":{"html":"https://cve.report/CVE-2026-16213","api":"https://cve.report/api/cve/CVE-2026-16213.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-16213","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-16213"},"summary":{"title":"Fantomas42 django-blog-zinnia Protected Entry Password entry_protection.py cleartext storage","description":"A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/entry_protection.py of the component Protected Entry Password Handler. The manipulation results in cleartext storage of sensitive information. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet.","state":"PUBLISHED","assigner":"VulDB","published_at":"2026-07-19 05:16:38","updated_at":"2026-07-20 14:16:55"},"problem_types":["CWE-310","CWE-312","CWE-312 Cleartext Storage of Sensitive Information","CWE-310 Cryptographic Issues"],"metrics":[{"version":"4.0","source":"cna@vuldb.com","type":"Secondary","score":"4.8","severity":"MEDIUM","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"DECLARED","score":"4.8","severity":"MEDIUM","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X","data":{"baseScore":4.8,"baseSeverity":"MEDIUM","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X","version":"4.0"}},{"version":"3.1","source":"cna@vuldb.com","type":"Secondary","score":"3.3","severity":"LOW","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.3,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"3.3","severity":"LOW","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R","data":{"baseScore":3.3,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R","version":"3.1"}},{"version":"3.0","source":"CNA","type":"DECLARED","score":"3.3","severity":"LOW","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R","data":{"baseScore":3.3,"baseSeverity":"LOW","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R","version":"3.0"}},{"version":"2.0","source":"cna@vuldb.com","type":"Secondary","score":"1.7","severity":"","vector":"AV:L/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:P/I:N/A:N","baseScore":1.7,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"CNA","type":"DECLARED","score":"1.7","severity":"","vector":"AV:L/AC:L/Au:S/C:P/I:N/A:N/E:ND/RL:ND/RC:UR","data":{"baseScore":1.7,"vectorString":"AV:L/AC:L/Au:S/C:P/I:N/A:N/E:ND/RL:ND/RC:UR","version":"2.0"}}],"references":[{"url":"https://github.com/Fantomas42/django-blog-zinnia/issues/595","name":"https://github.com/Fantomas42/django-blog-zinnia/issues/595","refsource":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vuldb.com/submit/857944","name":"https://vuldb.com/submit/857944","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/Fantomas42/django-blog-zinnia/","name":"https://github.com/Fantomas42/django-blog-zinnia/","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vuldb.com/cve/CVE-2026-16213","name":"https://vuldb.com/cve/CVE-2026-16213","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vuldb.com/vuln/380029","name":"https://vuldb.com/vuln/380029","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vuldb.com/vuln/380029/cti","name":"https://vuldb.com/vuln/380029/cti","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-16213","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16213","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.1","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.2","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.3","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.4","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.5","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.6","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.7","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.8","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.9","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.10","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.11","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.12","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.13","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.14","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.15","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.16","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.17","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.18","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.19","platforms":[]},{"source":"CNA","vendor":"Fantomas42","product":"django-blog-zinnia","version":"affected 0.20","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-07-18T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"source":"CNA","time":"2026-07-18T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"source":"CNA","time":"2026-07-18T10:57:48.000Z","lang":"en","value":"VulDB entry last update"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"GalaxynX (VulDB User)","lang":"en"},{"source":"CNA","value":"VulDB CNA Team","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"16213","cve":"CVE-2026-16213","epss":"0.000810000","percentile":"0.002610000","score_date":"2026-07-20","updated_at":"2026-07-21 00:13:14"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-16213","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-07-20T13:22:21.516443Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-07-20T13:22:26.672Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"references":[{"tags":["exploit"],"url":"https://github.com/Fantomas42/django-blog-zinnia/issues/595"}],"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:fantomas42:django-blog-zinnia:*:*:*:*:*:*:*:*"],"modules":["Protected Entry Password Handler"],"product":"django-blog-zinnia","vendor":"Fantomas42","versions":[{"status":"affected","version":"0.1"},{"status":"affected","version":"0.2"},{"status":"affected","version":"0.3"},{"status":"affected","version":"0.4"},{"status":"affected","version":"0.5"},{"status":"affected","version":"0.6"},{"status":"affected","version":"0.7"},{"status":"affected","version":"0.8"},{"status":"affected","version":"0.9"},{"status":"affected","version":"0.10"},{"status":"affected","version":"0.11"},{"status":"affected","version":"0.12"},{"status":"affected","version":"0.13"},{"status":"affected","version":"0.14"},{"status":"affected","version":"0.15"},{"status":"affected","version":"0.16"},{"status":"affected","version":"0.17"},{"status":"affected","version":"0.18"},{"status":"affected","version":"0.19"},{"status":"affected","version":"0.20"}]}],"credits":[{"lang":"en","type":"reporter","value":"GalaxynX (VulDB User)"},{"lang":"en","type":"coordinator","value":"VulDB CNA Team"}],"descriptions":[{"lang":"en","value":"A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/entry_protection.py of the component Protected Entry Password Handler. The manipulation results in cleartext storage of sensitive information. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet."}],"metrics":[{"cvssV4_0":{"baseScore":4.8,"baseSeverity":"MEDIUM","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X","version":"4.0"}},{"cvssV3_1":{"baseScore":3.3,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R","version":"3.1"}},{"cvssV3_0":{"baseScore":3.3,"baseSeverity":"LOW","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R","version":"3.0"}},{"cvssV2_0":{"baseScore":1.7,"vectorString":"AV:L/AC:L/Au:S/C:P/I:N/A:N/E:ND/RL:ND/RC:UR","version":"2.0"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-312","description":"Cleartext Storage of Sensitive Information","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-310","description":"Cryptographic Issues","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-19T04:00:09.228Z","orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB"},"references":[{"name":"VDB-380029 | Fantomas42 django-blog-zinnia Protected Entry Password entry_protection.py cleartext storage","tags":["vdb-entry"],"url":"https://vuldb.com/vuln/380029"},{"name":"VDB-380029 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"],"url":"https://vuldb.com/vuln/380029/cti"},{"name":"CVE-2026-16213 | CVE Analysis and Report","tags":["third-party-advisory"],"url":"https://vuldb.com/cve/CVE-2026-16213"},{"name":"Submit #857944 | Fantomas42 django-blog-zinnia 881101a9d1d455b2fc581d6f4ae0947cdd8126c6 CWE-312 Cleartext Storage of Sensitive Information","tags":["third-party-advisory"],"url":"https://vuldb.com/submit/857944"},{"tags":["issue-tracking"],"url":"https://github.com/Fantomas42/django-blog-zinnia/issues/595"},{"tags":["product"],"url":"https://github.com/Fantomas42/django-blog-zinnia/"}],"timeline":[{"lang":"en","time":"2026-07-18T00:00:00.000Z","value":"Advisory disclosed"},{"lang":"en","time":"2026-07-18T02:00:00.000Z","value":"VulDB entry created"},{"lang":"en","time":"2026-07-18T10:57:48.000Z","value":"VulDB entry last update"}],"title":"Fantomas42 django-blog-zinnia Protected Entry Password entry_protection.py cleartext storage"}},"cveMetadata":{"assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","assignerShortName":"VulDB","cveId":"CVE-2026-16213","datePublished":"2026-07-19T04:00:09.228Z","dateReserved":"2026-07-18T08:52:44.014Z","dateUpdated":"2026-07-20T13:22:26.672Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-19 05:16:38","lastModifiedDate":"2026-07-20 14:16:55","problem_types":["CWE-310","CWE-312","CWE-312 Cleartext Storage of Sensitive Information","CWE-310 Cryptographic Issues"],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.3,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:P/I:N/A:N","baseScore":1.7,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.1,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-20T13:22:21.516443Z","id":"CVE-2026-16213","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"16213","Ordinal":"1","Title":"Fantomas42 django-blog-zinnia Protected Entry Password entry_pro","CVE":"CVE-2026-16213","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"16213","Ordinal":"1","NoteData":"A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/entry_protection.py of the component Protected Entry Password Handler. The manipulation results in cleartext storage of sensitive information. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet.","Type":"Description","Title":"Fantomas42 django-blog-zinnia Protected Entry Password entry_pro"}]}}}