CWE-201
Insertion of Sensitive Information Into Sent Data
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
367 vulnerabilities with CWE-201
CVE-2026-4035
HIGH
MLflow < 3.11.0 - AI Gateway Secret Environment Variable Disclosure
CVSS 7.7
CVE-2026-44653
MEDIUM
LibreChat Shared MCP Server View Leaks Decrypted Admin Secrets
CVSS 6.5
CVE-2026-35447
MEDIUM
NamelessMC 2.2.4 - Private Profile Access Control Bypass and Cross-Profile Writes
CVE-2026-42673
HIGH
WordPress Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity plugin <= 3.3.6 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-49370
LOW
Jetbrains YouTrack < 2026.1.13162 - Insertion of Sensitive Information Into Sent Data
CVSS 3.4
CVE-2026-10101
MEDIUM
Assisted-service: assisted-service: infraenv status leaks referenced pull-secret contents to namespace view users
CVSS 6.3
CVE-2026-45582
MEDIUM
n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node parameters
CVSS 6.5
CVE-2026-42746
HIGH
WordPress Smart Online Order for Clover plugin <= 1.6.0 - Sensitive Data Exposure vulnerability
CVSS 7.3
CVE-2026-48877
MEDIUM
WordPress GenerateBlocks plugin <= 2.1.0 - Sensitive Data Exposure vulnerability
CVSS 6.5
CVE-2026-41181
MEDIUM
Traefik: Errors middleware forwards Authorization and Cookie headers to separate error page service
CVSS 5.8
CVE-2026-45215
MEDIUM
WordPress WP EasyPay plugin <= 4.3.0 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-42880
CRITICAL
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
CVSS 9.6
CVE-2026-42997
HIGH
OpenStack Ironic <26.1.6 - Auth Bypass
CVSS 7.7
CVE-2026-42379
HIGH
WordPress Templately plugin <= 3.6.1 - Sensitive Data Exposure vulnerability
CVSS 7.7
CVE-2026-42042
MEDIUM
Axios < 1.15.1 and < 0.31.1 - Cross-Site Request Forgery via withXSRFToken Truthy Value Bypass
CVSS 5.4
CVE-2026-5512
MEDIUM
GitHub Enterprise Server Mobile Upload Policy API - Private Repository Name Disclosure
CVSS 4.3
CVE-2026-40161
HIGH
Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL
CVSS 7.7
CVE-2026-40293
MEDIUM
OpenFGA Playground Preshared Key Exposure
CVSS 6.5
CVE-2026-4525
HIGH
Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header
CVSS 7.5
CVE-2026-5483
HIGH
Odh-dashboard: odh dashboard kubernetes service account exposure
CVSS 8.5
CVE-2026-39912
CRITICAL
v2board / Xboard Authentication Token Exposure via loginWithMailLink
CVSS 9.1
CVE-2026-39711
MEDIUM
WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-39709
MEDIUM
WordPress The Tribal plugin <= 1.3.4 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-39586
MEDIUM
WordPress RepairBuddy plugin <= 4.1132 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-39570
MEDIUM
WordPress 12 Step Meeting List plugin <= 3.19.9 - Sensitive Data Exposure vulnerability
CVSS 5.3
Details
Vulnerabilities
367