VYPR

CWE-1230

Exposure of Sensitive Information Through Metadata

BaseIncomplete

Description

The product prevents direct access to a resource containing sensitive information, but it does not sufficiently limit access to metadata that is derived from the original, sensitive information.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (26)

page 2 of 2
  • CVE-2024-10324MedJan 24, 2025
    risk 0.21cvss 4.3epss 0.00

    The RomethemeKit For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.2 via the register_controls function in widgets/offcanvas-rometheme.php. This makes it possible for authenticated attackers, with…

  • CVE-2024-8910MedSep 25, 2024
    risk 0.21cvss 4.3epss 0.00

    The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 via the render function in includes/widgets/htmega_accordion.php. This makes it possible for authenticated attackers,…

  • CVE-2025-8713LowAug 14, 2025
    risk 0.20cvss 3.1epss 0.00

    PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data…

  • CVE-2026-14351MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to view the title of a confidential issue through a publicly…

  • CVE-2025-48941MedJun 2, 2025
    risk 0.00cvss 5.3epss 0.00

    MyBB is free and open source forum software. Prior to version 1.8.39, the search component does not validate permissions correctly, which allows attackers to determine the existence of hidden (draft, unapproved, or soft-deleted) threads containing specified text in the title.…

  • CVE-2025-26527MedFeb 24, 2025
    risk 0.00cvss 5.3epss 0.00

    Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.