VYPR

CWE-201

Insertion of Sensitive Information Into Sent Data

BaseDraft

Description

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-217 · CAPEC-612 · CAPEC-613 · CAPEC-618 · CAPEC-619 · CAPEC-621 · CAPEC-622 · CAPEC-623

CVEs mapped to this weakness (388)

page 5 of 20
  • CVE-2023-6916HigApr 10, 2024
    risk 0.47cvss 7.2epss 0.01

    Audit records for OpenAPI requests may include sensitive information. This could lead to unauthorized accesses and privilege escalation.

  • CVE-2025-66566HigDec 5, 2025
    risk 0.46cvss epss 0.01

    yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via crafted compressed input. In applications where…

  • CVE-2025-8862HigAug 11, 2025
    risk 0.46cvss epss 0.00

    YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a version where this information is properly redacted.

  • CVE-2025-3529HigApr 23, 2025
    risk 0.46cvss 8.2epss 0.00

    The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.2 via the 'file_url' parameter. This makes it possible for unauthenticated attackers to view potentially sensitive information and…

  • CVE-2024-3502HigNov 14, 2024
    risk 0.46cvss 8.1epss 0.00

    In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists where account recovery hashes of users are inadvertently exposed to unauthorized actors. This issue occurs when authenticated users inspect responses from `GET /v1/users/me`…

  • CVE-2026-45049higJun 23, 2026
    risk 0.45cvss epss

    ## Summary **Description** An Information Exposure Through Sent Data (CWE-201) issue in OpenAM's Cross-Domain Single Sign-On (CDSSO) servlet allows a logged-in user's raw OpenAM session token to be POSTed to an attacker-controlled URL. This impacts OpenAM Community Edition…

  • CVE-2026-27868MedJun 17, 2026
    risk 0.45cvss epss 0.00

    An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could obtain privilege information by using the command Version via the path:…

  • CVE-2025-7708MedFeb 9, 2026
    risk 0.44cvss 6.8epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd. Co. K12net allows Communication Channel Manipulation. This issue affects k12net: through 26072025.

  • CVE-2026-4035HigJun 3, 2026
    risk 0.43cvss 7.7epss 0.00

    A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because…

  • CVE-2026-40161HigApr 21, 2026
    risk 0.43cvss 7.7epss 0.00

    Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a…

  • CVE-2025-66035HigNov 26, 2025
    risk 0.43cvss epss 0.01

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability…

  • CVE-2025-43768HigAug 23, 2025
    risk 0.43cvss 7.7epss 0.00

    Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows authenticated users without any permissions to access sensitive…

  • CVE-2026-47717HigAug 12, 2026
    risk 0.42cvss 7.5epss 0.01

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue.

  • CVE-2026-16637MedAug 7, 2026
    risk 0.42cvss 6.5epss 0.00

    OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.

  • CVE-2026-66901HigAug 4, 2026
    risk 0.42cvss 7.5epss 0.00

    Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the library requests are read from the credentials JSON, and their hosts were not checked against the universe…

  • CVE-2026-66339MedJul 24, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture…

  • CVE-2024-35690MedJun 17, 2026
    risk 0.42cvss 6.5epss 0.00

    Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded Sensitive Data. This issue affects Widget Options: from n/a through 4.0.1.

  • CVE-2026-54197MedJun 16, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.

  • CVE-2026-48965MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Sensitive Data Exposure in XCloner <= 4.8.6 versions.

  • CVE-2026-42384HigJun 15, 2026
    risk 0.42cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.