CWE-201
Insertion of Sensitive Information Into Sent Data
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
367 vulnerabilities with CWE-201
CVE-2026-39564
MEDIUM
WordPress Sunshine Photo Cart plugin < 3.6.2 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-39542
MEDIUM
WordPress Doofinder for WooCommerce plugin <= 2.10.13 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-39473
MEDIUM
WordPress Simple History plugin <= 5.24.0 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-20151
HIGH
Cisco Smart Software Manager On-Prem Privilege Escalation Vulnerability
CVSS 7.3
CVE-2026-4927
MEDIUM
Devolutions Server 2026.1.6-2026.1.11 - Info Disclosure
CVSS 6.5
CVE-2026-34226
HIGH
Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies
CVSS 7.5
CVE-2026-27877
MEDIUM
Public dashboards discloses all direct mode datasources
CVSS 6.5
CVE-2026-32538
HIGH
WordPress SMTP Mailer plugin <= 1.1.24 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-25339
MEDIUM
WordPress Contact Form by WPForms plugin <= 1.9.8.7 - Sensitive Data Exposure vulnerability
CVSS 6.5
CVE-2026-33180
HIGH
HAPI FHIR HTTP authentication leak in redirects
CVSS 7.5
CVE-2026-32829
HIGH
lz4_flex: Decompression can leak information from uninitialized memory or reused output buffer
CVSS 7.5
CVE-2026-27935
MEDIUM
Discourse leaks private topic metadata to non-authorized users
CVSS 6.5
CVE-2026-27934
HIGH
Discourse leaks private topic title and post excerpt via user action API endpoint
CVSS 7.5
CVE-2026-2578
MEDIUM
Information Disclosure via WebSocket Event When Deleting Unrevealed Burn on Read Posts
CVSS 4.3
CVE-2026-32354
MEDIUM
WpEvently < 5.1.9 - Sensitive Data Exposure via Embedded Data Retrieval
CVSS 5.3
CVE-2026-28481
MEDIUM
OpenClaw <2026.1.30 - Info Disclosure
CVSS 6.5
CVE-2026-27406
HIGH
My Tickets <=2.1.0 - Info Disclosure
CVSS 7.5
CVE-2026-27370
HIGH
Premio Chaty <=3.5.1 - Info Disclosure
CVSS 7.5
CVE-2026-23546
MEDIUM
RadiusTheme Classified Listing <=5.3.4 - Info Disclosure
CVSS 6.5
CVE-2026-28131
MEDIUM
WPVibes Elementor Addon Elements <=1.14.4 - Info Disclosure
CVSS 6.5
CVE-2026-1694
MEDIUM
PcVue 12.0.0-16.3.3 - Info Disclosure
CVSS 4.3
CVE-2026-27465
MEDIUM
Fleet < 4.80.1 - Authenticated Google Calendar Service Account Credential Exposure via Configuration API
CVSS 6.5
CVE-2026-27516
HIGH
Binardat 10G08-0800GSM <V300SP10260209 - Info Disclosure
CVSS 7.5
CVE-2026-27514
MEDIUM
Shenzhen Tenda F3 V12.01.01.55 - Info Disclosure
CVSS 6.5
CVE-2026-25008
MEDIUM
Ninja Tables <=5.2.5 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities
367