VYPR

CWE-201

Insertion of Sensitive Information Into Sent Data

BaseDraft

Description

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-217 · CAPEC-612 · CAPEC-613 · CAPEC-618 · CAPEC-619 · CAPEC-621 · CAPEC-622 · CAPEC-623

CVEs mapped to this weakness (420)

page 5 of 21
  • CVE-2023-49261HigJan 12, 2024
    risk 0.49cvss 7.5epss 0.00

    The "tokenKey" value used in user authorization is visible in the HTML source of the login page.

  • CVE-2020-8975HigOct 17, 2022
    risk 0.49cvss 7.5epss 0.01

    ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, allows a remote attacker with access to the web application and knowledge of the routes (URIs) used by the application, to access sensitive information about the system.

  • CVE-2016-10519HigMay 31, 2018
    risk 0.49cvss 7.5epss 0.02

    A security issue was found in bittorrent-dht before 5.1.3 that allows someone to send a specific series of messages to a listening peer and get it to reveal internal memory.

  • CVE-2026-52698HigJun 17, 2026
    risk 0.48cvss 7.4epss 0.00

    Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation & Chat Widget <= 4.2.3 versions.

  • CVE-2026-49082HigJun 15, 2026
    risk 0.48cvss 7.4epss 0.00

    Subscriber Sensitive Data Exposure in Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons <= 1.4.8 versions.

  • CVE-2026-46481HigJun 8, 2026
    risk 0.47cvss 8.3epss 0.00

    OpenMetadata is a unified metadata platform. Prior to version 1.12.4, a non-admin SSO user can trigger a TEST_CONNECTION workflow for a Database Service and receive, in the HTTP 201 response of POST /api/v1/automations/workflows, both the cleartext database password in…

  • CVE-2026-42746HigMay 27, 2026
    risk 0.47cvss 7.3epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Retrieve Embedded Sensitive Data.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0.

  • CVE-2026-20151HigApr 1, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to the improper transmission of sensitive user information. An…

  • CVE-2025-58098HigDec 5, 2025
    risk 0.47cvss 8.3epss 0.01

    Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version…

  • CVE-2023-6916HigApr 10, 2024
    risk 0.47cvss 7.2epss 0.01

    Audit records for OpenAPI requests may include sensitive information. This could lead to unauthorized accesses and privilege escalation.

  • CVE-2026-82209HigSep 6, 2026
    risk 0.46cvss 8.2epss 0.01

    When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`). Instead of…

  • CVE-2025-66566HigDec 5, 2025
    risk 0.46cvss —epss 0.01

    yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via crafted compressed input. In applications where…

  • CVE-2025-8862HigAug 11, 2025
    risk 0.46cvss —epss 0.00

    YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a version where this information is properly redacted.

  • CVE-2025-3529HigApr 23, 2025
    risk 0.46cvss 8.2epss 0.00

    The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.2 via the 'file_url' parameter. This makes it possible for unauthenticated attackers to view potentially sensitive information and…

  • CVE-2024-3502HigNov 14, 2024
    risk 0.46cvss 8.1epss 0.00

    In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists where account recovery hashes of users are inadvertently exposed to unauthorized actors. This issue occurs when authenticated users inspect responses from `GET /v1/users/me`…

  • CVE-2026-78374MedSep 10, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The front-end JSON editor endpoint exposes an action called contact that requires no authentication, no CSRF token, no captcha (when no captcha plugin is enabled)…

  • CVE-2026-78303MedSep 10, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing potential email manipulation.

  • CVE-2026-45049higJun 23, 2026
    risk 0.45cvss —epss —

    ## Summary **Description** An Information Exposure Through Sent Data (CWE-201) issue in OpenAM's Cross-Domain Single Sign-On (CDSSO) servlet allows a logged-in user's raw OpenAM session token to be POSTed to an attacker-controlled URL. This impacts OpenAM Community Edition…

  • CVE-2026-27868MedJun 17, 2026
    risk 0.45cvss —epss 0.00

    An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could obtain privilege information by using the command Version via the path:…

  • CVE-2026-65812MedSep 8, 2026
    risk 0.44cvss 6.8epss 0.00

    Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.