CWE-201

Insertion of Sensitive Information Into Sent Data

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

367 vulnerabilities with CWE-201
CVE-2026-39564 MEDIUM
WordPress Sunshine Photo Cart plugin < 3.6.2 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-39542 MEDIUM
WordPress Doofinder for WooCommerce plugin <= 2.10.13 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-39473 MEDIUM
WordPress Simple History plugin <= 5.24.0 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-20151 HIGH
Cisco Smart Software Manager On-Prem Privilege Escalation Vulnerability
CVSS 7.3
CVE-2026-4927 MEDIUM
Devolutions Server 2026.1.6-2026.1.11 - Info Disclosure
CVSS 6.5
CVE-2026-34226 HIGH
Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies
CVSS 7.5
CVE-2026-27877 MEDIUM
Public dashboards discloses all direct mode datasources
CVSS 6.5
CVE-2026-32538 HIGH
WordPress SMTP Mailer plugin <= 1.1.24 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-25339 MEDIUM
WordPress Contact Form by WPForms plugin <= 1.9.8.7 - Sensitive Data Exposure vulnerability
CVSS 6.5
CVE-2026-33180 HIGH
HAPI FHIR HTTP authentication leak in redirects
CVSS 7.5
CVE-2026-32829 HIGH
lz4_flex: Decompression can leak information from uninitialized memory or reused output buffer
CVSS 7.5
CVE-2026-27935 MEDIUM
Discourse leaks private topic metadata to non-authorized users
CVSS 6.5
CVE-2026-27934 HIGH
Discourse leaks private topic title and post excerpt via user action API endpoint
CVSS 7.5
CVE-2026-2578 MEDIUM
Information Disclosure via WebSocket Event When Deleting Unrevealed Burn on Read Posts
CVSS 4.3
CVE-2026-32354 MEDIUM
WpEvently < 5.1.9 - Sensitive Data Exposure via Embedded Data Retrieval
CVSS 5.3
CVE-2026-28481 MEDIUM
OpenClaw <2026.1.30 - Info Disclosure
CVSS 6.5
CVE-2026-27406 HIGH
My Tickets <=2.1.0 - Info Disclosure
CVSS 7.5
CVE-2026-27370 HIGH
Premio Chaty <=3.5.1 - Info Disclosure
CVSS 7.5
CVE-2026-23546 MEDIUM
RadiusTheme Classified Listing <=5.3.4 - Info Disclosure
CVSS 6.5
CVE-2026-28131 MEDIUM
WPVibes Elementor Addon Elements <=1.14.4 - Info Disclosure
CVSS 6.5
CVE-2026-1694 MEDIUM
PcVue 12.0.0-16.3.3 - Info Disclosure
CVSS 4.3
CVE-2026-27465 MEDIUM
Fleet < 4.80.1 - Authenticated Google Calendar Service Account Credential Exposure via Configuration API
CVSS 6.5
CVE-2026-27516 HIGH
Binardat 10G08-0800GSM <V300SP10260209 - Info Disclosure
CVSS 7.5
CVE-2026-27514 MEDIUM
Shenzhen Tenda F3 V12.01.01.55 - Info Disclosure
CVSS 6.5
CVE-2026-25008 MEDIUM
Ninja Tables <=5.2.5 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 367