VYPR

CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

BaseIncomplete

Description

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-170 · CAPEC-694

CVEs mapped to this weakness (406)

page 20 of 21
  • CVE-2026-59548HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.

  • CVE-2026-59528HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.00

    Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.

  • CVE-2026-65535MedJul 23, 2026
    risk 0.00cvss 4.3epss 0.00

    Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.

  • CVE-2026-65521MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.

  • CVE-2026-65505MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

  • CVE-2026-65474MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.

  • CVE-2026-61945MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.

  • CVE-2026-10588MedJul 16, 2026
    risk 0.00cvss 4.4epss 0.00

    A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.

  • CVE-2026-50294MedJul 14, 2026
    risk 0.00cvss 6.2epss 0.01

    Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.

  • CVE-2026-61977MedJul 13, 2026
    risk 0.00cvss 5.3epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2.

  • CVE-2026-61976MedJul 13, 2026
    risk 0.00cvss 5.3epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0.

  • CVE-2026-61975MedJul 13, 2026
    risk 0.00cvss 5.3epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1.

  • CVE-2026-57393MedJul 13, 2026
    risk 0.00cvss 6.5epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8.

  • CVE-2026-14808CriJul 6, 2026
    risk 0.00cvss 9.8epss 0.01

    Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain the database account and password.

  • CVE-2026-57753MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.

  • CVE-2026-56124HigJun 29, 2026
    risk 0.00cvss 7.5epss 0.01

    phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and…

  • CVE-2026-57664MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions.

  • CVE-2026-57633MedJun 26, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in WCBoost – Products Compare <= 1.1.0 versions.

  • CVE-2026-57316MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.

  • CVE-2026-56060HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.