CWE-201— Insertion of Sensitive Information Into Sent Data
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.— MITRE CWE catalog
451 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-201page 1 of 10
- CVE-2025-49408CRITICALCVSS 10.0EG 10.02025-08-20
Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data. This issue affects Templately: from n/a through 3.2.7.
- CVE-2026-5483CRITICALCVSS 9.9EG 9.92026-04-10
A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This c…
- CVE-2020-26085CRITICALCVSS 9.9EG 9.92021-01-07
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access t…
- CVE-2020-27134CRITICALCVSS 9.9EG 9.92020-12-11
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access t…
- CVE-2020-27133CRITICALCVSS 9.9EG 9.92020-12-11
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access t…
- CVE-2020-27132CRITICALCVSS 9.9EG 9.92020-12-11
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access t…
- CVE-2020-27127CRITICALCVSS 9.9EG 9.92020-12-11
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access t…
- CVE-2026-92555CRITICALCVSS 9.8EG 9.82026-10-08
Insertion of sensitive information into sent data vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. AKINSOFT WOLVOX Control Panel allows Pull Data from System Resources. This issue affects AKINSOFT WOLVOX C…
- CVE-2018-17245CRITICALCVSS 9.8EG 9.82018-12-20
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP …
- CVE-2026-106501CRITICALCVSS 9.6EG 9.62026-10-06
Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder. An authenticated Backstage…
- CVE-2026-42880CRITICALCVSS 9.6EG 9.62026-05-07
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allow…
- CVE-2024-7205CRITICALCVSS 9.4EG 9.42024-07-31
When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information.
- CVE-2025-26318CRITICALCVSS 5.8EG 9.42025-03-04
hb.exe in TSplus Remote Access before 17.30 2024-10-30 allows remote attackers to retrieve a list of all domain accounts currently connected to the application.
- CVE-2026-8924CRITICALCVSS 9.1EG 9.12026-07-03
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmit…
- CVE-2025-41118CRITICALCVSS 9.1EG 9.12026-04-15
Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to use Tencent COS as the storage backend, an attacker …
- CVE-2026-39912CRITICALCVSS 9.1EG 9.12026-04-09
V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_link_enable feature is active. Unauthenticated attackers can POST to the l…
- CVE-2025-48749CRITICALCVSS 9.1EG 9.12025-05-28
Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data.
- CVE-2024-3502CRITICALCVSS 8.1EG 9.12024-11-14
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists where account recovery hashes of users are inadvertently exposed to unauthorized actors. This issue occurs when authenticated users insp…
- CVE-2026-4035CRITICALCVSS 7.7EG 9.12026-06-03
A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlle…
- CVE-2021-26566CRITICALCVSS 8.3EG 9.02021-02-26
Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary commands via inbound QuickConnect traffic.
- CVE-2026-4525HIGHCVSS 8.8EG 8.82026-04-17
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, a…
- CVE-2023-48240HIGHCVSS 8.8EG 8.82023-11-20
XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents and not display a difference for an actually unchanged image. For this, XWiki requests all embedded images on the server…
- CVE-2025-11500HIGHCVSS 8.7EG 8.72026-03-16
Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms - one solely for interface management and one for protecting all other server resources. When the latter is turned off…
- CVE-2025-48045HIGHCVSS 8.7EG 8.72025-05-29
An unauthenticated HTTP GET request to the /client.php endpoint will disclose the default administrator user credentials.
- CVE-2026-67425HIGHCVSS 8.6EG 8.62026-07-29
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends them in the Authorization: Bearer header to…
- CVE-2023-3399HIGHCVSS 8.5EG 8.52023-11-06
An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or…
- CVE-2026-6267HIGHCVSS 5.3EG 8.52026-07-29
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to acces…
- CVE-2026-101322HIGHCVSS 8.3EG 8.32026-10-01
In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected infrastructure's `Authorization` header to outgoing requests without checking the destination origin. In dep…
- CVE-2026-54848HIGHCVSS 8.3EG 8.32026-06-25
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square... Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Se…
- CVE-2026-46481HIGHCVSS 8.3EG 8.32026-05-21
OpenMetadata is a unified metadata platform. Prior to version 1.12.4, a non-admin SSO user can trigger a TEST_CONNECTION workflow for a Database Service and receive, in the HTTP 201 response of POST /api/v1/automations/workflows, both the …
- CVE-2025-58098HIGHCVSS 8.3EG 8.32025-12-05
Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users …
- CVE-2025-24858HIGHCVSS 8.3EG 8.32025-01-26
Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash algorithm used by Develocity was chosen according to best p…
- CVE-2026-82209HIGHCVSS 8.2EG 8.22026-09-06
When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Doma…
- CVE-2025-66566HIGHCVSS 8.2EG 8.22025-12-05
yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via crafted co…
- CVE-2025-3529HIGHCVSS 8.2EG 8.22025-04-23
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.2 via the 'file_url' parameter. This makes it possible for unauthenticated attackers to view …
- CVE-2026-27516HIGHCVSS 7.5EG 8.12026-02-24
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior expose user passwords in plaintext within the administrative interface and HTTP responses, allowing recovery of valid credentials.
- CVE-2024-8890HIGHCVSS 8.0EG 8.02024-09-18
An attacker with access to the network where the CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could obtain legitimate credentials or steal sessions due to the fact that the device only implements the HTTP protocol. This fact pr…
- CVE-2021-23019HIGHCVSS 7.8EG 7.82021-06-01
The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGINX support package.
- CVE-2026-105849HIGHCVSS 7.7EG 7.72026-10-06
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, users with ordinary read access to other authentication documents in a collection with u…
- CVE-2026-42997HIGHCVSS 7.7EG 7.72026-05-05
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides a…
- CVE-2026-42379HIGHCVSS 7.7EG 7.72026-04-27
Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data.This issue affects Templately: from n/a through 3.6.1.
- CVE-2026-40161HIGHCVSS 7.7EG 7.72026-04-21
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the Tekton Pipelines git resolver in API mode sends the syst…
- CVE-2025-66035HIGHCVSS 7.7EG 7.72025-11-26
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in…
- CVE-2025-9958HIGHCVSS 7.7EG 7.72025-09-26
An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry config…
- CVE-2025-43768HIGHCVSS 7.7EG 7.72025-08-23
Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows authenticated users without a…
- CVE-2024-23506HIGHCVSS 7.7EG 7.72024-01-27
Insertion of Sensitive Information Into Sent Data vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.9.
- CVE-2024-7872HIGHCVSS 7.6EG 7.62025-03-06
Insertion of Sensitive Information Into Sent Data vulnerability in ExtremePACS Extreme XDS allows Retrieve Embedded Sensitive Data. This issue affects Extreme XDS: before 3933.
- CVE-2023-28117HIGHCVSS 7.6EG 7.62023-03-22
Sentry SDK is the official Python SDK for Sentry, real-time crash reporting software. When using the Django integration of versions prior to 1.14.0 of the Sentry SDK in a specific configuration it is possible to leak sensitive cookies valu…
- CVE-2026-105071HIGHCVSS 7.5EG 7.52026-10-06
Unauthenticated Sensitive Data Exposure in SiteVault – Backup, Restore, Migration & Cloning <= 1.5.17 versions.
- CVE-2026-104385HIGHCVSS 7.5EG 7.52026-10-06
Unauthenticated Sensitive Data Exposure in Groundhogg <= 4.8.3 versions.
Map vulnerabilities like CWE-201 to your infrastructure
EchelonGraph correlates every CVE — across CWE-201 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →