CWE-201
Insertion of Sensitive Information Into Sent Data
Description
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-217 · CAPEC-612 · CAPEC-613 · CAPEC-618 · CAPEC-619 · CAPEC-621 · CAPEC-622 · CAPEC-623
CVEs mapped to this weakness (388)
page 19 of 20| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-16798 | Med | 0.00 | 6.5 | 0.00 | Jul 24, 2026 | Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses… | ||
| CVE-2026-27372 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions. | ||
| CVE-2026-12547 | Low | 0.00 | 3.4 | 0.00 | Jul 21, 2026 | SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy,… | ||
| CVE-2026-7488 | Hig | 0.00 | 7.5 | 0.00 | Jul 17, 2026 | Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: through 03062026. | ||
| CVE-2026-7189 | Hig | 0.00 | 7.5 | 0.00 | Jul 17, 2026 | Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Proliz's OBS: before v3.6.0. | ||
| CVE-2026-56460 | Med | 0.00 | 6.5 | 0.00 | Jul 9, 2026 | HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system. | ||
| CVE-2026-1365 | Med | 0.00 | 6.5 | 0.00 | Jul 9, 2026 | Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentication Bypass. This issue affects OSOS: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||
| CVE-2026-59519 | Med | 0.00 | 5.3 | 0.00 | Jul 5, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6. | ||
| CVE-2026-59511 | Med | 0.00 | 5.3 | 0.00 | Jul 5, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9. | ||
| CVE-2026-57347 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions. | ||
| CVE-2025-69132 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions. | ||
| CVE-2026-57736 | Hig | 0.00 | 7.4 | 0.00 | Jul 1, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. This issue affects HubSpot: from n/a through 11.3.51. | ||
| CVE-2026-13211 | Med | 0.00 | 4.3 | 0.00 | Jul 1, 2026 | The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or “Admin” role. | ||
| CVE-2026-12085 | Med | 0.00 | 6.5 | 0.00 | Jun 30, 2026 | IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy could disclose sensitive configurations and secrets to authenticated users in API responses that could be used… | ||
| CVE-2026-13437 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in… | ||
| CVE-2026-57318 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions. | ||
| CVE-2026-54834 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions. | ||
| CVE-2026-54848 | Hig | 0.00 | 8.3 | 0.00 | Jun 25, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3. | ||
| CVE-2026-54841 | Hig | 0.00 | 7.5 | 0.00 | Jun 25, 2026 | Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions. | ||
| CVE-2026-54821 | Hig | 0.00 | 7.4 | 0.00 | Jun 25, 2026 | Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions. |
- risk 0.00cvss 6.5epss 0.00
Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses…
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.
- risk 0.00cvss 3.4epss 0.00
SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy,…
- risk 0.00cvss 7.5epss 0.00
Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: through 03062026.
- risk 0.00cvss 7.5epss 0.00
Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Proliz's OBS: before v3.6.0.
- risk 0.00cvss 6.5epss 0.00
HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
- risk 0.00cvss 6.5epss 0.00
Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentication Bypass. This issue affects OSOS: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
- risk 0.00cvss 5.3epss 0.00
Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6.
- risk 0.00cvss 5.3epss 0.00
Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9.
- risk 0.00cvss 6.5epss 0.00
Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.
- risk 0.00cvss 7.4epss 0.00
Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. This issue affects HubSpot: from n/a through 11.3.51.
- risk 0.00cvss 4.3epss 0.00
The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or “Admin” role.
- risk 0.00cvss 6.5epss 0.00
IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy could disclose sensitive configurations and secrets to authenticated users in API responses that could be used…
- risk 0.00cvss 6.5epss 0.00
Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in…
- risk 0.00cvss 6.5epss 0.00
Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.
- risk 0.00cvss 8.3epss 0.00
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.
- risk 0.00cvss 7.4epss 0.00
Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.