VYPR

CWE-201

Insertion of Sensitive Information Into Sent Data

BaseDraft

Description

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-217 · CAPEC-612 · CAPEC-613 · CAPEC-618 · CAPEC-619 · CAPEC-621 · CAPEC-622 · CAPEC-623

CVEs mapped to this weakness (388)

page 19 of 20
  • CVE-2026-16798MedJul 24, 2026
    risk 0.00cvss 6.5epss 0.00

    Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses…

  • CVE-2026-27372MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.

  • CVE-2026-12547LowJul 21, 2026
    risk 0.00cvss 3.4epss 0.00

    SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy,…

  • CVE-2026-7488HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: through 03062026.

  • CVE-2026-7189HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Proliz's OBS: before v3.6.0.

  • CVE-2026-56460MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.

  • CVE-2026-1365MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentication Bypass. This issue affects OSOS: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

  • CVE-2026-59519MedJul 5, 2026
    risk 0.00cvss 5.3epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6.

  • CVE-2026-59511MedJul 5, 2026
    risk 0.00cvss 5.3epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9.

  • CVE-2026-57347MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.

  • CVE-2025-69132MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.

  • CVE-2026-57736HigJul 1, 2026
    risk 0.00cvss 7.4epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. This issue affects HubSpot: from n/a through 11.3.51.

  • CVE-2026-13211MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or “Admin” role.

  • CVE-2026-12085MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy could disclose sensitive configurations and secrets to authenticated users in API responses that could be used…

  • CVE-2026-13437MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in…

  • CVE-2026-57318MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.

  • CVE-2026-54834HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.

  • CVE-2026-54848HigJun 25, 2026
    risk 0.00cvss 8.3epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3.

  • CVE-2026-54841HigJun 25, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.

  • CVE-2026-54821HigJun 25, 2026
    risk 0.00cvss 7.4epss 0.00

    Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.