CWE-201
Insertion of Sensitive Information Into Sent Data
Description
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-217 · CAPEC-612 · CAPEC-613 · CAPEC-618 · CAPEC-619 · CAPEC-621 · CAPEC-622 · CAPEC-623
CVEs mapped to this weakness (420)
page 2 of 21| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-48240 | Cri | 0.52 | 9.0 | 0.01 | Nov 20, 2023 | XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents and not display a difference for an actually unchanged image. For this, XWiki requests all embedded images on the server side. These requests are also sent for… | ||
| CVE-2021-23019 | Hig | 0.51 | 7.8 | 0.00 | Jun 1, 2021 | The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGINX support package. | ||
| CVE-2026-42997 | Hig | 0.50 | 7.7 | 0.00 | May 5, 2026 | An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic… | ||
| CVE-2026-42379 | Hig | 0.50 | 7.7 | 0.00 | Apr 27, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data.This issue affects Templately: from n/a through 3.6.1. | ||
| CVE-2025-9958 | Hig | 0.50 | 7.7 | 0.01 | Sep 26, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations. | ||
| CVE-2024-23506 | Hig | 0.50 | 7.7 | 0.01 | Jan 27, 2024 | Insertion of Sensitive Information Into Sent Data vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.9. | ||
| CVE-2026-78336 | Hig | 0.49 | 7.5 | 0.00 | Sep 14, 2026 | Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client… | ||
| CVE-2026-81804 | Hig | 0.49 | 7.5 | 0.00 | Sep 10, 2026 | Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions. | ||
| CVE-2026-66585 | Hig | 0.49 | 7.5 | 0.00 | Aug 24, 2026 | Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions. | ||
| CVE-2026-75953 | Hig | 0.49 | 7.5 | 0.00 | Aug 19, 2026 | Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address. | ||
| CVE-2026-73386 | Hig | 0.49 | 7.5 | 0.00 | Aug 19, 2026 | Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions. | ||
| CVE-2026-73384 | Hig | 0.49 | 7.5 | 0.00 | Aug 19, 2026 | Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions. | ||
| CVE-2026-66463 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions. | ||
| CVE-2026-66443 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions. | ||
| CVE-2026-65543 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions. | ||
| CVE-2026-67425 | Hig | 0.49 | 8.6 | 0.00 | Jul 29, 2026 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends them in the Authorization: Bearer header to caller-controlled base_url, allowing an… | ||
| CVE-2026-13380 | Hig | 0.49 | 7.5 | 0.00 | Jul 20, 2026 | VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is… | ||
| CVE-2026-34888 | Hig | 0.49 | 7.5 | 0.00 | Jun 17, 2026 | Unauthenticated Sensitive Data Exposure in Bricksforge <= 3.1.8.4 versions. | ||
| CVE-2026-52695 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2026 | Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions. | ||
| CVE-2026-52692 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2026 | Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions. |
- risk 0.52cvss 9.0epss 0.01
XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents and not display a difference for an actually unchanged image. For this, XWiki requests all embedded images on the server side. These requests are also sent for…
- risk 0.51cvss 7.8epss 0.00
The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGINX support package.
- risk 0.50cvss 7.7epss 0.00
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic…
- risk 0.50cvss 7.7epss 0.00
Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data.This issue affects Templately: from n/a through 3.6.1.
- risk 0.50cvss 7.7epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.
- risk 0.50cvss 7.7epss 0.01
Insertion of Sensitive Information Into Sent Data vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.9.
- risk 0.49cvss 7.5epss 0.00
Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client…
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.
- risk 0.49cvss 7.5epss 0.00
Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
- risk 0.49cvss 7.5epss 0.00
Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
- risk 0.49cvss 8.6epss 0.00
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends them in the Authorization: Bearer header to caller-controlled base_url, allowing an…
- risk 0.49cvss 7.5epss 0.00
VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is…
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Bricksforge <= 3.1.8.4 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.