CWE-201— Insertion of Sensitive Information Into Sent Data
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.— MITRE CWE catalog
451 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-201page 2 of 10
- CVE-2026-42413HIGHCVSS 7.5EG 7.52026-10-06
Unauthenticated Sensitive Data Exposure in Snapshotify – All-in-One Backup & Restore & Migrate <= 1.3.2 versions.
- CVE-2026-41562HIGHCVSS 7.5EG 7.52026-10-06
Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions.
- CVE-2026-41561HIGHCVSS 7.5EG 7.52026-10-06
Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions.
- CVE-2026-41559HIGHCVSS 7.5EG 7.52026-10-06
Unauthenticated Sensitive Data Exposure in SafeSnap – Verified WordPress Backup & Restore <= 2.1.2 versions.
- CVE-2026-41563HIGHCVSS 7.5EG 7.52026-10-06
Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.
- CVE-2026-103334HIGHCVSS 7.5EG 7.52026-10-05
Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations restaurant-reservations allows Retrieve Embedded Sensitive Data.This issue affects Five Star Restaurant Res…
- CVE-2026-97307HIGHCVSS 7.5EG 7.52026-10-04
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.
- CVE-2026-97241HIGHCVSS 7.5EG 7.52026-09-30
Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions.
- CVE-2026-97240HIGHCVSS 7.5EG 7.52026-09-30
Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions.
- CVE-2026-86450HIGHCVSS 7.5EG 7.52026-09-29
Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobile …
- CVE-2026-78336HIGHCVSS 7.5EG 7.52026-09-14
Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all …
- CVE-2026-81804HIGHCVSS 7.5EG 7.52026-09-10
Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions.
- CVE-2026-80255HIGHCVSS 7.5EG 7.52026-09-06
A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent ov…
- CVE-2026-55553HIGHCVSS 7.5EG 7.52026-08-25
urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prior to 4.9.1 and 2.44.1, urllib follows redirects through followRedirect but reuses caller-supplied options across origin…
- CVE-2026-66585HIGHCVSS 7.5EG 7.52026-08-24
Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.
- CVE-2026-75953HIGHCVSS 7.5EG 7.52026-08-19
Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to…
- CVE-2026-73386HIGHCVSS 7.5EG 7.52026-08-19
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.
- CVE-2026-73384HIGHCVSS 7.5EG 7.52026-08-19
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
- CVE-2026-66463HIGHCVSS 7.5EG 7.52026-08-13
Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.
- CVE-2026-66443HIGHCVSS 7.5EG 7.52026-08-13
Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
- CVE-2026-65543HIGHCVSS 7.5EG 7.52026-08-06
Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
- CVE-2026-66901HIGHCVSS 7.5EG 7.52026-08-04
Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the library requests are read from the credentials JSON, and their hos…
- CVE-2026-13380HIGHCVSS 7.5EG 7.52026-07-20
VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within…
- CVE-2026-7488HIGHCVSS 7.5EG 7.52026-07-17
Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: through 03062026.
- CVE-2026-7189HIGHCVSS 7.5EG 7.52026-07-17
Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Proliz's OBS: before v3.6.0.
- CVE-2026-54834HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.
- CVE-2026-54841HIGHCVSS 7.5EG 7.52026-06-25
Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.
- CVE-2026-34888HIGHCVSS 7.5EG 7.52026-06-17
Unauthenticated Sensitive Data Exposure in Bricksforge <= 3.1.8.4 versions.
- CVE-2026-52692HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.
- CVE-2026-52695HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.
- CVE-2026-42667HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions.
- CVE-2026-40789HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions.
- CVE-2026-42384HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.
- CVE-2026-39480HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Sensitive Data Exposure in Backup Migration <= 2.1.1 versions.
- CVE-2026-49064HIGHCVSS 7.5EG 7.52026-06-15
Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data. This issue affects GetPaid: from n/a through 2.8.49.
- CVE-2026-44487HIGHCVSS 7.5EG 7.52026-06-04
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. Th…
- CVE-2026-44486HIGHCVSS 7.5EG 7.52026-06-04
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticat…
- CVE-2026-42673HIGHCVSS 7.5EG 7.52026-06-01
Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data. This issue affects Activity L…
- CVE-2026-49370HIGHCVSS 7.5EG 7.52026-05-29
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
- CVE-2026-47717HIGHCVSS 7.5EG 7.52026-05-27
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled…
- CVE-2026-34226HIGHCVSS 7.5EG 7.52026-03-27
Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Versions prior to 20.8.9 may attach cookies from the current page origin (`window.location`) instead of the request target URL when `fetch(...,…
- CVE-2026-32538HIGHCVSS 7.5EG 7.52026-03-25
Insertion of Sensitive Information Into Sent Data vulnerability in Noor Alam SMTP Mailer smtp-mailer allows Retrieve Embedded Sensitive Data.This issue affects SMTP Mailer: from n/a through <= 1.1.24.
- CVE-2026-33180HIGHCVSS 7.5EG 7.52026-03-20
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.0, when setting headers in HTTP requests, the internal HTTP client sends headers first to the host in the initial…
- CVE-2026-32829HIGHCVSS 7.5EG 7.52026-03-20
lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0, decompressing invalid LZ4 data can leak sensitive information from uninitialized memory or from previous decompression oper…
- CVE-2026-27934HIGHCVSS 7.5EG 7.52026-03-19
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack of visibility checks with a user action API endpoint that results in disclosure of the title and post excerpt to unaut…
- CVE-2026-28481HIGHCVSS 7.5EG 7.52026-03-05
OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS Teams attachment downloader (optional extension must be enabled) that leaks bearer tokens to allowlisted suffix domain…
- CVE-2026-27406HIGHCVSS 7.5EG 7.52026-03-05
Insertion of Sensitive Information Into Sent Data vulnerability in Joe Dolson My Tickets my-tickets allows Retrieve Embedded Sensitive Data.This issue affects My Tickets: from n/a through <= 2.1.0.
- CVE-2026-27370HIGHCVSS 7.5EG 7.52026-03-05
Insertion of Sensitive Information Into Sent Data vulnerability in Premio Chaty chaty allows Retrieve Embedded Sensitive Data.This issue affects Chaty: from n/a through <= 3.5.1.
- CVE-2020-37150HIGHCVSS 7.5EG 7.52026-02-05
Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, which discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by sending a GET request t…
- CVE-2020-37093HIGHCVSS 7.5EG 7.52026-02-03
Netis E1+ 1.2.32533 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve WiFi passwords through the netcore_get.cgi endpoint. Attackers can send a GET request to the endpoint to extract sensiti…
Map vulnerabilities like CWE-201 to your infrastructure
EchelonGraph correlates every CVE — across CWE-201 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →