CWE-201

Insertion of Sensitive Information Into Sent Data

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

367 vulnerabilities with CWE-201
CVE-2026-24427 MEDIUM
Shenzhen Tenda AC7 <V03.03.03.01_cn - Info Disclosure
CVSS 5.5
CVE-2026-24992 MEDIUM
WPFactory Advanced WooCommerce Product Sales Reporting <4.1.2 - Inf...
CVSS 5.3
CVE-2026-1539 MEDIUM
libsoup - Proxy-Authorization Header Credential Disclosure
CVSS 5.8
CVE-2026-24477 HIGH
AnythingLLM <1.10.0 - Info Disclosure
CVSS 7.5
CVE-2026-24430 HIGH
Shenzhen Tenda W30E V2 <16.01.0.19(5037) - Info Disclosure
CVSS 7.5
CVE-2026-24589 MEDIUM
Cargus eCommerce Cargus <= 1.5.8 - Sensitive Data Exposure via Embedded Data Retrieval
CVSS 5.3
CVE-2026-24565 MEDIUM
bPlugins B Accordion <2.0.0 - Info Disclosure
CVSS 6.5
CVE-2026-24559 MEDIUM
CRM Perks Integration for Contact Form 7 HubSpot <1.4.3 - Info Disc...
CVSS 5.3
CVE-2026-24557 MEDIUM
WEN Solutions Contact Form 7 GetResponse Extension <1.0.9 - Info Di...
CVSS 5.3
CVE-2026-23878 MEDIUM
HotCRP - Unauthenticated Sensitive Information Disclosure via Document API
CVSS 6.5
CVE-2026-22246 MEDIUM
Mastodon < 4.3.17 - Unauthenticated Information Disclosure via Severed Relationship Notifications
CVSS 6.5
CVE-2026-22539 MEDIUM
EFACEC QC 60/90/120 - Unauthenticated Information Disclosure via OCPP v1.6
CVE-2025-69132 MEDIUM
WordPress Corpkit theme <= 1.0.5 - Sensitive Data Exposure vulnerability
CVSS 6.5
CVE-2025-62309 LOW
HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields.
CVSS 2.6
CVE-2025-62308 MEDIUM
HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed
CVSS 5.1
CVE-2025-62305 MEDIUM
HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions
CVSS 5.1
CVE-2025-31978 MEDIUM
HCL BigFix Service Management (SM) does not adequately sanitize or safely render
CVSS 4.6
CVE-2025-41118 CRITICAL
Sensitive COS `SecretKey` exposed in plaintext via configuration API due to missing type protection
CVSS 9.1
CVE-2025-11500 HIGH
Credentials exposure in tinycontrol devices
CVE-2025-14483 MEDIUM
IBM Sterling B2B Integrator 6.1.0.0-6.1.2.7_2 - Info Disclosure
CVSS 4.3
CVE-2025-68515 MEDIUM
WP Booking System <=2.0.19.12 - Info Disclosure
CVSS 5.8
CVE-2025-68855 MEDIUM
JobBoard Job listing <=1.2.8 - Info Disclosure
CVSS 5.9
CVE-2025-7708 MEDIUM
Atlas Educational Software Industry Ltd. Co. K12net <09022026 - Inf...
CVSS 6.8
CVE-2025-15329 MEDIUM
Tanium Threat Response 4.5.0-4.5.250 - Information Disclosure
CVSS 4.9
CVE-2025-67857 MEDIUM
moodle < 4.1.21 and >= 0 < 4.1.22 - Unauthenticated User Identifier Exposure in Anonymous Assignment Submission URLs
CVSS 4.3
Details
Vulnerabilities 367