CWE-201
Insertion of Sensitive Information Into Sent Data
Description
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-217 · CAPEC-612 · CAPEC-613 · CAPEC-618 · CAPEC-619 · CAPEC-621 · CAPEC-622 · CAPEC-623
CVEs mapped to this weakness (420)
page 21 of 21| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-59511 | Med | 0.00 | 5.3 | 0.00 | Jul 5, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9. | ||
| CVE-2026-57347 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions. | ||
| CVE-2025-69132 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions. | ||
| CVE-2026-57736 | Hig | 0.00 | 7.4 | 0.00 | Jul 1, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. This issue affects HubSpot: from n/a through 11.3.51. | ||
| CVE-2026-13211 | Med | 0.00 | 4.3 | 0.00 | Jul 1, 2026 | The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or “Admin” role. | ||
| CVE-2026-12085 | Med | 0.00 | 6.5 | 0.00 | Jun 30, 2026 | IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy could disclose sensitive configurations and secrets to authenticated users in API responses that could be used… | ||
| CVE-2026-13437 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in… | ||
| CVE-2026-57318 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions. | ||
| CVE-2026-54834 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions. | ||
| CVE-2026-54848 | Hig | 0.00 | 8.3 | 0.00 | Jun 25, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3. | ||
| CVE-2026-54841 | Hig | 0.00 | 7.5 | 0.00 | Jun 25, 2026 | Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions. | ||
| CVE-2026-54821 | Hig | 0.00 | 7.4 | 0.00 | Jun 25, 2026 | Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions. | ||
| CVE-2026-23878 | Med | 0.00 | 6.5 | 0.00 | Jan 19, 2026 | HotCRP is conference review software. Starting in commit aa20ef288828b04550950cf67c831af8a525f508 and prior to commit ceacd5f1476458792c44c6a993670f02c984b4a0, authors with at least one submission on a HotCRP site could use the document API to download any documents (PDFs,… | ||
| CVE-2026-22246 | Med | 0.00 | 6.5 | 0.00 | Jan 8, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Mastodon 4.3 added notifications of severed relationships, allowing end-users to inspect the relationships they lost as the result of a moderation action. The code allowing users to download lists of… | ||
| CVE-2025-31134 | Hig | 0.00 | 7.5 | 0.00 | Jun 4, 2025 | FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, an attacker can gain additional information about the server by checking if certain directories exist. An attacker can, for example, check if older PHP versions are installed or if certain software is… | ||
| CVE-2025-48381 | Med | 0.00 | 4.3 | 0.00 | May 30, 2025 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. In versions starting from 2.4.0 to before 2.38.0, an authenticated CVAT user may be able to retrieve the IDs and names of all tasks, projects, labels, and the IDs of all… | ||
| CVE-2024-50633 | Non | 0.00 | 0.0 | 0.01 | Jan 16, 2025 | A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the Supplier because the product intentionally lets all users… | ||
| CVE-2024-5213 | Med | 0.00 | 6.5 | 0.00 | Jun 20, 2024 | In mintplex-labs/anything-llm versions up to and including 1.5.3, an issue was discovered where the password hash of a user is returned in the response after login (`POST /api/request-token`) and after account creations (`POST /api/admin/users/new`). This exposure occurs because… | ||
| CVE-2020-27784 | Med | 0.00 | 5.5 | 0.00 | Sep 1, 2022 | A vulnerability was found in the Linux kernel, where accessing a deallocated instance in printer_ioctl() printer_ioctl() tries to access of a printer_dev instance. However, use-after-free arises because it had been freed by gprinter_free(). | ||
| CVE-2017-2582 | Med | 0.00 | 6.5 | 0.02 | Jul 26, 2018 | It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by… |
- risk 0.00cvss 5.3epss 0.00
Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9.
- risk 0.00cvss 6.5epss 0.00
Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.
- risk 0.00cvss 7.4epss 0.00
Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. This issue affects HubSpot: from n/a through 11.3.51.
- risk 0.00cvss 4.3epss 0.00
The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or “Admin” role.
- risk 0.00cvss 6.5epss 0.00
IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy could disclose sensitive configurations and secrets to authenticated users in API responses that could be used…
- risk 0.00cvss 6.5epss 0.00
Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in…
- risk 0.00cvss 6.5epss 0.00
Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.
- risk 0.00cvss 8.3epss 0.00
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.
- risk 0.00cvss 7.4epss 0.00
Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.
- risk 0.00cvss 6.5epss 0.00
HotCRP is conference review software. Starting in commit aa20ef288828b04550950cf67c831af8a525f508 and prior to commit ceacd5f1476458792c44c6a993670f02c984b4a0, authors with at least one submission on a HotCRP site could use the document API to download any documents (PDFs,…
- risk 0.00cvss 6.5epss 0.00
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon 4.3 added notifications of severed relationships, allowing end-users to inspect the relationships they lost as the result of a moderation action. The code allowing users to download lists of…
- risk 0.00cvss 7.5epss 0.00
FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, an attacker can gain additional information about the server by checking if certain directories exist. An attacker can, for example, check if older PHP versions are installed or if certain software is…
- risk 0.00cvss 4.3epss 0.00
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. In versions starting from 2.4.0 to before 2.38.0, an authenticated CVAT user may be able to retrieve the IDs and names of all tasks, projects, labels, and the IDs of all…
- risk 0.00cvss 0.0epss 0.01
A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the Supplier because the product intentionally lets all users…
- risk 0.00cvss 6.5epss 0.00
In mintplex-labs/anything-llm versions up to and including 1.5.3, an issue was discovered where the password hash of a user is returned in the response after login (`POST /api/request-token`) and after account creations (`POST /api/admin/users/new`). This exposure occurs because…
- risk 0.00cvss 5.5epss 0.00
A vulnerability was found in the Linux kernel, where accessing a deallocated instance in printer_ioctl() printer_ioctl() tries to access of a printer_dev instance. However, use-after-free arises because it had been freed by gprinter_free().
- risk 0.00cvss 6.5epss 0.02
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by…