CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

367 vulnerabilities with CWE-497
CVE-2026-57664 MEDIUM
WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.1.6 - Sensitive Data Exposure vulnerability
CVSS 4.3
CVE-2026-57633 MEDIUM
WordPress WCBoost &#8211; Products Compare plugin <= 1.1.0 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-57316 MEDIUM
WordPress GetGenie plugin <= 4.4.2 - Sensitive Data Exposure vulnerability
CVSS 6.5
CVE-2026-56060 HIGH
WordPress Print Invoice & Delivery Notes for WooCommerce plugin <= 7.1.1 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-54824 HIGH
WordPress Ads by WPQuads plugin <= 3.0.3 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-9307 MEDIUM
Rockwell CompactLogix 5370 v36 - CIP Connection ID Disclosure
CVE-2026-52694 HIGH
WordPress Signature Add-On for WooCommerce plugin <= 2.0 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-49068 HIGH
WordPress Coupon Affiliates plugin <= 7.8.1 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-49066 HIGH
WordPress Conekta Payment Gateway plugin <= 6.0.0 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-49056 HIGH
WordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin <= 4.9.4 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-48878 MEDIUM
WordPress Visual Link Preview plugin <= 2.4.1 - Sensitive Data Exposure vulnerability
CVSS 6.5
CVE-2026-42660 MEDIUM
WordPress Contest Gallery plugin <= 28.1.7 - Sensitive Data Exposure vulnerability
CVSS 6.5
CVE-2026-40796 MEDIUM
WordPress WPPizza plugin <= 3.19.9 - Sensitive Data Exposure vulnerability
CVSS 6.5
CVE-2026-34891 HIGH
WordPress IDPay Payment Gateway for Woocommerce plugin <= 2.2.5 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-24618 MEDIUM
WordPress Hash Elements plugin <= 1.5.4 - Sensitive Data Exposure vulnerability
CVSS 4.3
CVE-2026-0466 MEDIUM
Amd µProf - Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVSS 5.5
CVE-2026-44743 LOW
SAP BusinessObjects - Sensitive Information Exposure via Endpoint
CVSS 3.7
CVE-2026-49077 MEDIUM
WordPress WP eMember plugin <= v10.2.2 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-44749 MEDIUM
Information Disclosure vulnerability in SAP Gateway
CVSS 4.3
CVE-2026-27349 MEDIUM
WordPress Mail Mint plugin <= 1.19.5 - Sensitive Data Exposure vulnerability
CVSS 4.3
CVE-2026-0240 HIGH
Trust Protection Foundation: Sensitive Information Disclosure Vulnerability
CVSS 8.7
CVE-2026-0239 MEDIUM
Chronosphere Chronocollector Information Disclosure Vulnerability
CVSS 6.5
CVE-2026-43654 HIGH
iOS and iPadOS < 18.7.9 - Unauthorized Sensitive System Information Exposure
CVSS 7.5
CVE-2026-7864 MEDIUM
SEPPmail Secure Email Gateway - Environment Variable Exposure
CVE-2026-41928 MEDIUM
Vvveb < 1.0.8.2 Information Disclosure via Cron Controller
CVSS 5.3
Details
Vulnerabilities 367