CWE-201— Insertion of Sensitive Information Into Sent Data
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.— MITRE CWE catalog
364 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-201page 8 of 8
- CVE-2026-5512MEDIUMCVSS 4.3EG 4.32026-04-21
An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to determine the names of private repositories by their numeric ID. The mobile upload policy API endpoint did not per…
- CVE-2026-55180MEDIUMCVSS 6.5EG 6.52026-06-25
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-workspace.yaml into registry request destinations and registry credentials. A malicious re…
- CVE-2026-56460MEDIUMCVSS 6.5EG 6.52026-07-09
HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
- CVE-2026-57318MEDIUMCVSS 6.5EG 6.52026-06-26
Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.
- CVE-2026-57347MEDIUMCVSS 6.5EG 6.52026-07-02
Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
- CVE-2026-57736HIGHCVSS 7.4EG 7.42026-07-01
Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. This issue affects HubSpot: from n/a through 11.3.51.
- CVE-2026-59511MEDIUMCVSS 5.3EG 5.32026-07-05
Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9.
- CVE-2026-59519MEDIUMCVSS 5.3EG 5.32026-07-05
Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6.
- CVE-2026-64643MEDIUMCVSS 6.3EG 6.32026-07-22
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache endpoints can be disclose…
- CVE-2026-65434MEDIUMCVSS 6.5EG 6.52026-07-27
Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.
- CVE-2026-66339MEDIUMCVSS 6.5EG 6.52026-07-24
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This all…
- CVE-2026-7184MEDIUMCVSS 6.5EG 6.52026-06-12
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, which allows authenticated users with the {{manage_secure_connections}} permission to obtain …
- CVE-2026-7189HIGHCVSS 7.5EG 7.52026-07-17
Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Proliz's OBS: before v3.6.0.
- CVE-2026-7488HIGHCVSS 7.5EG 7.52026-07-17
Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: through 03062026.
Map vulnerabilities like CWE-201 to your infrastructure
EchelonGraph correlates every CVE — across CWE-201 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →