VYPR

CWE-201

Insertion of Sensitive Information Into Sent Data

BaseDraft

Description

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-217 · CAPEC-612 · CAPEC-613 · CAPEC-618 · CAPEC-619 · CAPEC-621 · CAPEC-622 · CAPEC-623

CVEs mapped to this weakness (420)

page 2 of 21
  • CVE-2023-48240CriNov 20, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents and not display a difference for an actually unchanged image. For this, XWiki requests all embedded images on the server side. These requests are also sent for…

  • CVE-2021-23019HigJun 1, 2021
    risk 0.51cvss 7.8epss 0.00

    The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGINX support package.

  • CVE-2026-42997HigMay 5, 2026
    risk 0.50cvss 7.7epss 0.00

    An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic…

  • CVE-2026-42379HigApr 27, 2026
    risk 0.50cvss 7.7epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data.This issue affects Templately: from n/a through 3.6.1.

  • CVE-2025-9958HigSep 26, 2025
    risk 0.50cvss 7.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.

  • CVE-2024-23506HigJan 27, 2024
    risk 0.50cvss 7.7epss 0.01

    Insertion of Sensitive Information Into Sent Data vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.9.

  • CVE-2026-78336HigSep 14, 2026
    risk 0.49cvss 7.5epss 0.00

    Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client…

  • CVE-2026-81804HigSep 10, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions.

  • CVE-2026-66585HigAug 24, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.

  • CVE-2026-75953HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.

  • CVE-2026-73386HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.

  • CVE-2026-73384HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.

  • CVE-2026-66463HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.

  • CVE-2026-66443HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.

  • CVE-2026-65543HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.

  • CVE-2026-67425HigJul 29, 2026
    risk 0.49cvss 8.6epss 0.00

    Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends them in the Authorization: Bearer header to caller-controlled base_url, allowing an…

  • CVE-2026-13380HigJul 20, 2026
    risk 0.49cvss 7.5epss 0.00

    VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is…

  • CVE-2026-34888HigJun 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Bricksforge <= 3.1.8.4 versions.

  • CVE-2026-52695HigJun 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.

  • CVE-2026-52692HigJun 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.