VYPR

CWE-201

Insertion of Sensitive Information Into Sent Data

BaseDraft

Description

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-217 · CAPEC-612 · CAPEC-613 · CAPEC-618 · CAPEC-619 · CAPEC-621 · CAPEC-622 · CAPEC-623

CVEs mapped to this weakness (420)

page 6 of 21
  • CVE-2026-86497MedSep 7, 2026
    risk 0.44cvss 6.8epss 0.00

    In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials

  • CVE-2025-7708MedFeb 9, 2026
    risk 0.44cvss 6.8epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd. Co. K12net allows Communication Channel Manipulation. This issue affects k12net: through 26072025.

  • CVE-2026-4035HigJun 3, 2026
    risk 0.43cvss 7.7epss 0.01

    A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because…

  • CVE-2026-40161HigApr 21, 2026
    risk 0.43cvss 7.7epss 0.00

    Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a…

  • CVE-2025-66035HigNov 26, 2025
    risk 0.43cvss —epss 0.01

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability…

  • CVE-2025-43768HigAug 23, 2025
    risk 0.43cvss 7.7epss 0.00

    Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows authenticated users without any permissions to access sensitive…

  • CVE-2026-80255HigSep 6, 2026
    risk 0.42cvss 7.5epss 0.01

    A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests…

  • CVE-2026-81280MedAug 31, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions.

  • CVE-2026-55553HigAug 25, 2026
    risk 0.42cvss 7.5epss 0.00

    urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prior to 4.9.1 and 2.44.1, urllib follows redirects through followRedirect but reuses caller-supplied options across origins. In src/HttpClient.ts,…

  • CVE-2026-28174MedAug 13, 2026
    risk 0.42cvss 6.5epss 0.00

    Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.

  • CVE-2026-47717HigAug 12, 2026
    risk 0.42cvss 7.5epss 0.01

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue.

  • CVE-2026-16637MedAug 7, 2026
    risk 0.42cvss 6.5epss 0.00

    OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.

  • CVE-2026-66901HigAug 4, 2026
    risk 0.42cvss 7.5epss 0.00

    Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the library requests are read from the credentials JSON, and their hosts were not checked against the universe…

  • CVE-2026-67322HigAug 1, 2026
    risk 0.42cvss 7.5epss 0.00

    GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking git clone. An attacker who…

  • CVE-2026-66339MedJul 24, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture…

  • CVE-2024-35690MedJun 17, 2026
    risk 0.42cvss 6.5epss 0.00

    Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded Sensitive Data. This issue affects Widget Options: from n/a through 4.0.1.

  • CVE-2026-54197MedJun 16, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.

  • CVE-2026-48965MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Sensitive Data Exposure in XCloner <= 4.8.6 versions.

  • CVE-2026-42384HigJun 15, 2026
    risk 0.42cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.

  • CVE-2026-49064HigJun 15, 2026
    risk 0.42cvss 7.5epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data. This issue affects GetPaid: from n/a through 2.8.49.