CWE-201— Insertion of Sensitive Information Into Sent Data
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.— MITRE CWE catalog
411 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-201page 8 of 9
- CVE-2026-54649LOWCVSS 2.1EG 2.12026-09-17
punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops the added Reply-To…
- CVE-2026-54660HIGHCVSS 7.4EG 7.42026-07-29
swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemoteRequestHeaders forwards --authorizationToken to every URL fetched by fetchRemoteSchemaDo…
- CVE-2026-54821HIGHCVSS 7.4EG 7.42026-06-25
Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.
- CVE-2026-5483CRITICALCVSS 9.9EG 9.92026-04-10
A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This c…
- CVE-2026-54834HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.
- CVE-2026-54841HIGHCVSS 7.5EG 7.52026-06-25
Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.
- CVE-2026-54848HIGHCVSS 8.3EG 8.32026-06-25
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square... Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Se…
- CVE-2026-5512MEDIUMCVSS 4.3EG 4.32026-04-21
An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to determine the names of private repositories by their numeric ID. The mobile upload policy API endpoint did not per…
- CVE-2026-55180MEDIUMCVSS 6.5EG 6.52026-06-25
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-workspace.yaml into registry request destinations and registry credentials. A malicious re…
- CVE-2026-55553HIGHCVSS 7.5EG 7.52026-08-25
urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prior to 4.9.1 and 2.44.1, urllib follows redirects through followRedirect but reuses caller-supplied options across origin…
- CVE-2026-56460MEDIUMCVSS 6.5EG 6.52026-07-09
HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
- CVE-2026-57318MEDIUMCVSS 6.5EG 6.52026-06-26
Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.
- CVE-2026-57347MEDIUMCVSS 6.5EG 6.52026-07-02
Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
- CVE-2026-57736HIGHCVSS 7.4EG 7.42026-07-01
Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. This issue affects HubSpot: from n/a through 11.3.51.
- CVE-2026-59511MEDIUMCVSS 5.3EG 5.32026-07-05
Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9.
- CVE-2026-59519MEDIUMCVSS 5.3EG 5.32026-07-05
Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6.
- CVE-2026-59809MEDIUMCVSS 4.9EG 4.92026-08-22
SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL conta…
- CVE-2026-62088MEDIUMCVSS 5.3EG 5.32026-09-11
Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. This issue affects ElasticPress: from n/a through 5.3.4.
- CVE-2026-6267HIGHCVSS 5.3EG 8.52026-07-29
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to acces…
- CVE-2026-63481MEDIUMCVSS 6.9EG 6.92026-08-20
Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier, the redirect handling in packages/hurl/src/http/client.rs strips Authorization and Cookie headers and basic-auth crede…
- CVE-2026-64643MEDIUMCVSS 5.3EG 5.32026-07-22
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache endpoints can be disclose…
- CVE-2026-64652LOWCVSS 3.3EG 3.32026-08-06
GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in certain fine-grained personal access tokens and GitHub App tokens. As a result, part of…
- CVE-2026-65434MEDIUMCVSS 6.5EG 6.52026-07-27
Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.
- CVE-2026-65543HIGHCVSS 7.5EG 7.52026-08-06
Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
- CVE-2026-65812MEDIUMCVSS 6.8EG 6.82026-09-08
Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
- CVE-2026-66339MEDIUMCVSS 6.5EG 6.52026-07-24
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This all…
- CVE-2026-66443HIGHCVSS 7.5EG 7.52026-08-13
Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
- CVE-2026-66463HIGHCVSS 7.5EG 7.52026-08-13
Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.
- CVE-2026-66585HIGHCVSS 7.5EG 7.52026-08-24
Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.
- CVE-2026-66683MEDIUMCVSS 5.3EG 5.32026-08-06
Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
- CVE-2026-66684MEDIUMCVSS 5.3EG 5.32026-08-06
Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.
- CVE-2026-66685MEDIUMCVSS 5.3EG 5.32026-08-06
Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
- CVE-2026-66696MEDIUMCVSS 4.3EG 4.32026-08-06
Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
- CVE-2026-66901HIGHCVSS 7.5EG 7.52026-08-04
Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the library requests are read from the credentials JSON, and their hos…
- CVE-2026-67354MEDIUMCVSS 5.9EG 5.92026-08-01
guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') fr…
- CVE-2026-67355MEDIUMCVSS 5.9EG 5.92026-08-01
guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intende…
- CVE-2026-67425HIGHCVSS 8.6EG 8.62026-07-29
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends them in the Authorization: Bearer header to…
- CVE-2026-7184MEDIUMCVSS 6.5EG 6.52026-06-12
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, which allows authenticated users with the {{manage_secure_connections}} permission to obtain …
- CVE-2026-7189HIGHCVSS 7.5EG 7.52026-07-17
Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Proliz's OBS: before v3.6.0.
- CVE-2026-73384HIGHCVSS 7.5EG 7.52026-08-19
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
- CVE-2026-73386HIGHCVSS 7.5EG 7.52026-08-19
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.
- CVE-2026-74008MEDIUMCVSS 5.3EG 5.32026-08-18
Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.
- CVE-2026-7488HIGHCVSS 7.5EG 7.52026-07-17
Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: through 03062026.
- CVE-2026-75953HIGHCVSS 7.5EG 7.52026-08-19
Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to…
- CVE-2026-77123MEDIUMCVSS 6.0EG 6.02026-09-02
Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the nexus:capabilities:read privilege can retrieve the plaintext shared secret configured on a webhook capability, …
- CVE-2026-78303MEDIUMCVSS 6.9EG 6.92026-09-10
Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing potent…
- CVE-2026-78336HIGHCVSS 7.5EG 7.52026-09-14
Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all …
- CVE-2026-78374MEDIUMCVSS 6.9EG 6.92026-09-10
Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The front-end JSON editor endpoint exposes an action called contact that requires no authentication, no CSRF token, no captc…
- CVE-2026-80255HIGHCVSS 7.5EG 7.52026-09-06
A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent ov…
- CVE-2026-81162MEDIUMCVSS 5.3EG 5.32026-09-02
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal vers…
Map vulnerabilities like CWE-201 to your infrastructure
EchelonGraph correlates every CVE — across CWE-201 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →