VYPR

CWE-201

Insertion of Sensitive Information Into Sent Data

BaseDraft

Description

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-217 · CAPEC-612 · CAPEC-613 · CAPEC-618 · CAPEC-619 · CAPEC-621 · CAPEC-622 · CAPEC-623

CVEs mapped to this weakness (388)

page 11 of 20
  • CVE-2025-58226MedSep 22, 2025
    risk 0.35cvss 5.3epss 0.01

    Insertion of Sensitive Information Into Sent Data vulnerability in iberezansky 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery interactive-3d-flipbook-powered-physics-engine allows Retrieve Embedded Sensitive Data.This issue affects 3D FlipBook – PDF Flipbook…

  • CVE-2025-55750MedAug 29, 2025
    risk 0.35cvss 6.5epss 0.00

    Gitpod is a developer platform for cloud development environments. In versions before main-gha.33628 for both Gitpod Classic and Gitpod Classic Enterprise, OAuth integration with Bitbucket in certain conditions allowed a crafted link to expose a valid Bitbucket access token via…

  • CVE-2025-24582MedJan 24, 2025
    risk 0.35cvss 5.3epss 0.01

    Insertion of Sensitive Information Into Sent Data vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Retrieve Embedded Sensitive Data.This issue affects 12 Step Meeting List: from n/a through <= 3.16.5.

  • CVE-2024-43283MedAug 26, 2024
    risk 0.35cvss 5.3epss 0.01

    Insertion of Sensitive Information Into Sent Data vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery: from n/a through <= 23.1.2.

  • CVE-2024-25148MedFeb 8, 2024
    risk 0.35cvss 5.4epss 0.01

    In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions the `doAsUserId` URL parameter may get leaked when creating linked content using the WYSIWYG editor and while…

  • CVE-2023-34968MedJul 20, 2023
    risk 0.35cvss 5.3epss 0.01

    A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC…

  • CVE-2023-1975MedApr 11, 2023
    risk 0.35cvss 6.5epss 0.01

    Insertion of Sensitive Information Into Sent Data in GitHub repository answerdev/answer prior to 1.0.8.

  • CVE-2022-27779MedJun 2, 2022
    risk 0.35cvss 5.3epss 0.03

    libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without [Public Suffix List](https://publicsuffix.org/)awareness. If PSL…

  • CVE-2021-1129MedJan 20, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to access general…

  • CVE-2020-25703MedNov 19, 2020
    risk 0.35cvss 5.3epss 0.02

    The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

  • CVE-2020-5364MedMay 20, 2020
    risk 0.35cvss 5.3epss 0.01

    Dell EMC Isilon OneFS versions 8.2.2 and earlier contain an SNMPv2 vulnerability. The SNMPv2 services is enabled, by default, with a pre-configured community string. This community string allows read-only access to many aspects of the Isilon cluster, some of which are considered…

  • CVE-2019-14849MedDec 12, 2019
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized information.

  • CVE-2026-66685MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.

  • CVE-2026-66684MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.

  • CVE-2026-66683MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.

  • CVE-2026-35447MedJun 2, 2026
    risk 0.34cvss epss 0.00

    NamelessMC is website software for Minecraft servers. In version 2.2.4, the profile page (modules/Core/pages/profile.php) processes wall post submissions and replies before verifying whether the viewer is authorized to access the profile. This allows any user with the…

  • CVE-2026-45215MedMay 12, 2026
    risk 0.34cvss 5.3epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Retrieve Embedded Sensitive Data.This issue affects WP EasyPay: from n/a through <= 4.3.0.

  • CVE-2026-39711MedApr 8, 2026
    risk 0.34cvss 5.3epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Retrieve Embedded Sensitive Data.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

  • CVE-2026-39709MedApr 8, 2026
    risk 0.34cvss 5.3epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in thetechtribe The Tribal the-tech-tribe allows Retrieve Embedded Sensitive Data.This issue affects The Tribal: from n/a through <= 1.3.4.

  • CVE-2026-39586MedApr 8, 2026
    risk 0.34cvss 5.3epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through <= 4.1132.