CWE-201

Insertion of Sensitive Information Into Sent Data

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

367 vulnerabilities with CWE-201
CVE-2026-54834 HIGH
WordPress Object Cache 4 everyone plugin <= 2.3.2 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-55180 MEDIUM
pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
CVSS 6.5
CVE-2026-54848 HIGH
WordPress APIExperts Square for WooCommerce plugin <= 4.7.3 - Sensitive Data Exposure vulnerability
CVSS 8.3
CVE-2026-54841 HIGH
WordPress Vitepos plugin <= 3.4.2 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-54821 HIGH
WordPress Visual Link Preview plugin <= 2.3.1 - Sensitive Data Exposure vulnerability
CVSS 7.4
CVE-2026-22551 MEDIUM
Eclipse Theia < 1.71.0 - Insertion of Sensitive Information Into Sent Data
CVSS 6.5
CVE-2026-52698 HIGH
WordPress PushEngage – Web Push Notifications, eCommerce Automation & Chat Widget plugin <= 4.2.3 - Sensitive Data Exposure vulnerability
CVSS 7.4
CVE-2026-34888 HIGH
WordPress Bricksforge plugin <= 3.1.8.4 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-27868 MEDIUM
PUBLICATION OF SENSITIVE INFORMATION ON REGESTA SMART HD-PLC OF TELDAT
CVE-2026-54197 MEDIUM
WordPress GetGenie plugin <= 4.4.1 - Sensitive Data Exposure vulnerability
CVSS 6.5
CVE-2026-52695 HIGH
WordPress ABC Crypto Checkout plugin <= 1.8.2 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-52692 HIGH
WordPress Affiliates Manager plugin <= 2.9.50 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-49082 HIGH
WordPress Chatway Live Chat <= 1.4.8 - Subscriber Data Exposure
CVSS 7.4
CVE-2026-48965 MEDIUM
WordPress XCloner plugin <= 4.8.6 - Sensitive Data Exposure vulnerability
CVSS 6.5
CVE-2026-42667 HIGH
WordPress Bookly plugin <= 27.4 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-42384 HIGH
WordPress Simply Schedule Appointments plugin < 1.6.11.2 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-40789 HIGH
WordPress Amelia plugin <= 2.2 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-39480 HIGH
WordPress Backup Migration plugin <= 2.1.1 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-49064 HIGH
WordPress GetPaid plugin <= 2.8.49 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-7184 MEDIUM
Mattermost Remote Cluster PATCH API Leaks Authentication Tokens
CVSS 6.5
CVE-2026-44487 HIGH
Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
CVSS 7.5
CVE-2026-44486 HIGH
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
CVSS 7.5
CVE-2026-46481 HIGH
OpenMetadata: TEST_CONNECTION workflow leaks ingestion-bot JWT and database password to regular users
CVSS 8.3
CVE-2026-42539 MEDIUM
IRIS <2.4.28 - Excessive Data Exposure
CVSS 6.5
CVE-2026-45739 LOW
Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs
CVSS 3.1
Details
Vulnerabilities 367