VYPR

CWE-201

Insertion of Sensitive Information Into Sent Data

BaseDraft

Description

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-217 · CAPEC-612 · CAPEC-613 · CAPEC-618 · CAPEC-619 · CAPEC-621 · CAPEC-622 · CAPEC-623

CVEs mapped to this weakness (388)

page 18 of 20
  • CVE-2025-67857MedFeb 3, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewers to see internal user IDs, compromising the intended anonymity and potentially leading to information…

  • CVE-2025-58246MedSep 23, 2025
    risk 0.21cvss 4.3epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges…

  • CVE-2025-55710MedAug 14, 2025
    risk 0.21cvss 4.3epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in Steve Burge TaxoPress simple-tags allows Retrieve Embedded Sensitive Data.This issue affects TaxoPress: from n/a through <= 3.37.2.

  • CVE-2024-25150MedFeb 20, 2024
    risk 0.21cvss 4.3epss 0.00

    Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions allows remote authenticated users to obtain a user's full…

  • CVE-2025-31363LowApr 16, 2025
    risk 0.20cvss 3.0epss 0.00

    Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to contact upstream which allows an authenticated user to exfiltrate data from an arbitrary server accessible to the victim via performing a prompt…

  • CVE-2024-32028MedApr 12, 2024
    risk 0.20cvss 4.1epss 0.00

    OpenTelemetry dotnet is a dotnet telemetry framework. In affected versions of `OpenTelemetry.Instrumentation.Http` and `OpenTelemetry.Instrumentation.AspNetCore` the `url.full` writes attribute/tag on spans (`Activity`) when tracing is enabled for outgoing http requests and…

  • CVE-2023-1825LowJun 7, 2023
    risk 0.20cvss 3.1epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. It was possible to disclose issue notes to an unauthorized user at project export.

  • CVE-2025-49300LowDec 16, 2025
    risk 0.18cvss 2.7epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in shinetheme Traveler Option Tree custom-option-tree allows Retrieve Embedded Sensitive Data.This issue affects Traveler Option Tree: from n/a through <= 2.8.

  • CVE-2025-64299LowNov 21, 2025
    risk 0.18cvss 2.7epss 0.00

    LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' password hashes.

  • CVE-2022-45428LowDec 27, 2022
    risk 0.18cvss 2.7epss 0.01

    Some Dahua software products have a vulnerability of sensitive information leakage. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can obtain the debugging information.

  • CVE-2021-32653LowJun 1, 2021
    risk 0.18cvss 2.7epss 0.01

    Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server versions prior to 19.0.11, 20.0.10, or 21.0.2 send user IDs to the lookup server even if the user has no fields set to published. The vulnerability is patched in versions 19.0.11, 20.0.10, and…

  • CVE-2025-62309LowMay 14, 2026
    risk 0.17cvss 2.6epss 0.00

    HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may allow sensitive information to be stored in the browser, potentially leading to unintended exposure under specific conditions.

  • CVE-2021-21416LowApr 1, 2021
    risk 0.17cvss 3.7epss 0.00

    django-registration is a user registration package for Django. The django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not…

  • CVE-2020-1770LowMar 27, 2020
    risk 0.16cvss 2.4epss 0.01

    Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

  • CVE-2026-44970LowJul 16, 2026
    risk 0.13cvss 3.1epss 0.00

    dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_called_event() in src/dbt_mcp/tracking/tracking.py serialized every MCP tool call's complete arguments dictionary and sent it through…

  • CVE-2026-45739LowJun 4, 2026
    risk 0.13cvss 3.1epss 0.00

    Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor into the browser URL query string. If a user entered a sensitive header, such as `Authorization:…

  • CVE-2024-38372LowJul 8, 2024
    risk 0.06cvss 2.0epss 0.00

    Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch()` request, `response.arrayBuffer()` might include portion of memory from the Node.js process. This has been patched in v6.19.2.

  • CVE-2026-20484MedAug 3, 2026
    risk 0.00cvss 4.4epss 0.00

    In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue…

  • CVE-2026-6267HigJul 29, 2026
    risk 0.00cvss 8.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to…

  • CVE-2026-65434MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.