CWE-201

Insertion of Sensitive Information Into Sent Data

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

367 vulnerabilities with CWE-201
CVE-2026-4035 HIGH
MLflow < 3.11.0 - AI Gateway Secret Environment Variable Disclosure
CVSS 7.7
CVE-2026-44653 MEDIUM
LibreChat Shared MCP Server View Leaks Decrypted Admin Secrets
CVSS 6.5
CVE-2026-35447 MEDIUM
NamelessMC 2.2.4 - Private Profile Access Control Bypass and Cross-Profile Writes
CVE-2026-42673 HIGH
WordPress Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity plugin <= 3.3.6 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-49370 LOW
Jetbrains YouTrack < 2026.1.13162 - Insertion of Sensitive Information Into Sent Data
CVSS 3.4
CVE-2026-10101 MEDIUM
Assisted-service: assisted-service: infraenv status leaks referenced pull-secret contents to namespace view users
CVSS 6.3
CVE-2026-45582 MEDIUM
n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node parameters
CVSS 6.5
CVE-2026-42746 HIGH
WordPress Smart Online Order for Clover plugin <= 1.6.0 - Sensitive Data Exposure vulnerability
CVSS 7.3
CVE-2026-48877 MEDIUM
WordPress GenerateBlocks plugin <= 2.1.0 - Sensitive Data Exposure vulnerability
CVSS 6.5
CVE-2026-41181 MEDIUM
Traefik: Errors middleware forwards Authorization and Cookie headers to separate error page service
CVSS 5.8
CVE-2026-45215 MEDIUM
WordPress WP EasyPay plugin <= 4.3.0 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-42880 CRITICAL
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
CVSS 9.6
CVE-2026-42997 HIGH
OpenStack Ironic <26.1.6 - Auth Bypass
CVSS 7.7
CVE-2026-42379 HIGH
WordPress Templately plugin <= 3.6.1 - Sensitive Data Exposure vulnerability
CVSS 7.7
CVE-2026-42042 MEDIUM
Axios < 1.15.1 and < 0.31.1 - Cross-Site Request Forgery via withXSRFToken Truthy Value Bypass
CVSS 5.4
CVE-2026-5512 MEDIUM
GitHub Enterprise Server Mobile Upload Policy API - Private Repository Name Disclosure
CVSS 4.3
CVE-2026-40161 HIGH
Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL
CVSS 7.7
CVE-2026-40293 MEDIUM
OpenFGA Playground Preshared Key Exposure
CVSS 6.5
CVE-2026-4525 HIGH
Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header
CVSS 7.5
CVE-2026-5483 HIGH
Odh-dashboard: odh dashboard kubernetes service account exposure
CVSS 8.5
CVE-2026-39912 CRITICAL
v2board / Xboard Authentication Token Exposure via loginWithMailLink
CVSS 9.1
CVE-2026-39711 MEDIUM
WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-39709 MEDIUM
WordPress The Tribal plugin <= 1.3.4 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-39586 MEDIUM
WordPress RepairBuddy plugin <= 4.1132 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-39570 MEDIUM
WordPress 12 Step Meeting List plugin <= 3.19.9 - Sensitive Data Exposure vulnerability
CVSS 5.3
Details
Vulnerabilities 367