CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

367 vulnerabilities with CWE-497
CVE-2026-58246 MEDIUM
SAP NetWeaver ABAP Platform - Diagnostic Trace Session Identifier Disclosure
CVSS 4.3
CVE-2026-66438 MEDIUM
WordPress Exclusive Addons Elementor plugin <= 2.8.0 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-65564 MEDIUM
WordPress MapPress Maps for WordPress plugin <= 2.97.6 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-59548 HIGH
WordPress Byteflows Travel & Hotel Booking plugin <= 1.0.0 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-59528 HIGH
WordPress ShipTime: Discounted Shipping Rates plugin <= 1.1.1 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-44955 MEDIUM
Exposure of Sensitive System Information to an Unauthorized Control Sphere in Panduit IntraVUE by Pronetiqs
CVSS 5.3
CVE-2026-28698 HIGH
Exposure of Sensitive System Information to an Unauthorized Control Sphere in Panduit IntraVUE by Pronetiqs
CVSS 8.6
CVE-2026-65535 MEDIUM
WordPress TinyMCE Templates plugin <= 4.8.1 - Sensitive Data Exposure vulnerability
CVSS 4.3
CVE-2026-65521 MEDIUM
WordPress WP Social Ninja plugin <= 4.3.0 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-65505 MEDIUM
WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-65498 MEDIUM
WordPress Complianz plugin <= 7.5.0 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-65490 MEDIUM
WordPress Create by Mediavine plugin <= 2.5.3 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-65474 MEDIUM
WordPress Ninja Tables plugin <= 5.2.10 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-65458 MEDIUM
WordPress Polylang plugin <= 3.8.5 - Sensitive Data Exposure vulnerability
CVSS 4.3
CVE-2026-61945 MEDIUM
WordPress WooCommerce Product Stock Alert plugin <= 3.0.6 - Sensitive Data Exposure vulnerability
CVSS 6.5
CVE-2026-10588 MEDIUM
Lenovo Yoga Pro 7 15IPH11 and Multiple Legion/IdeaPad BIOS - System Management Mode Memory Address Disclosure
CVSS 4.4
CVE-2026-50294 MEDIUM
Microsoft Windows 10 Version 1607 - Windows Kernel Information Disclosure Vulnerability
CVSS 6.2
CVE-2026-61977 MEDIUM
WordPress JetSearch plugin <= 3.6.1.2 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-61976 MEDIUM
WordPress JetBlocks For Elementor plugin <= 1.5.0 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-61975 MEDIUM
WordPress JetReviews plugin <= 3.0.1 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-57393 MEDIUM
WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Sensitive Data Exposure vulnerability
CVSS 6.5
CVE-2026-14808 CRITICAL
PROG MIS|Prog Management System - Exposure of Sensitive Information
CVSS 9.8
CVE-2026-55726 MEDIUM
Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVSS 5.3
CVE-2026-57753 MEDIUM
WordPress Kit (formerly ConvertKit) for WooCommerce plugin <= 2.1.5 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-56124 HIGH
phpUploader < 2.0.2 Unauthenticated Database Exposure via index model
CVSS 7.5
Details
Vulnerabilities 367