CWE-497— Exposure of Sensitive System Information to an Unauthorized Control Sphere
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.— MITRE CWE catalog
404 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-497page 8 of 9
- CVE-2026-49077MEDIUMCVSS 5.3EG 5.32026-06-04
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue affects WP eMember: from n/a through v10.2.2.
- CVE-2026-50294MEDIUMCVSS 6.2EG 6.22026-07-14
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.
- CVE-2026-52694HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.
- CVE-2026-54824HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.
- CVE-2026-55726MEDIUMCVSS 5.3EG 5.32026-07-03
The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access any device log file available in the blob storage container.
- CVE-2026-56060HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.
- CVE-2026-56124HIGHCVSS 7.5EG 7.52026-06-29
phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index mode…
- CVE-2026-56569MEDIUMCVSS 3.3EG 4.02026-07-31
HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
- CVE-2026-57316MEDIUMCVSS 6.5EG 6.52026-06-26
Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.
- CVE-2026-57393MEDIUMCVSS 6.5EG 6.52026-07-13
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoi…
- CVE-2026-57633MEDIUMCVSS 5.3EG 5.32026-06-26
Unauthenticated Sensitive Data Exposure in WCBoost – Products Compare <= 1.1.0 versions.
- CVE-2026-57664MEDIUMCVSS 4.3EG 4.32026-06-26
Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions.
- CVE-2026-57753MEDIUMCVSS 5.3EG 5.32026-07-02
Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.
- CVE-2026-58246MEDIUMCVSS 4.3EG 4.32026-07-28
SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could…
- CVE-2026-59528HIGHCVSS 7.5EG 7.52026-07-27
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
- CVE-2026-59548HIGHCVSS 7.5EG 7.52026-07-27
Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.
- CVE-2026-61911MEDIUMCVSS 4.3EG 4.32026-09-09
An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mail…
- CVE-2026-61945MEDIUMCVSS 6.5EG 6.52026-07-23
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a…
- CVE-2026-61975MEDIUMCVSS 5.3EG 5.32026-07-13
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1.
- CVE-2026-61976MEDIUMCVSS 5.3EG 5.32026-07-13
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through …
- CVE-2026-61977MEDIUMCVSS 5.3EG 5.32026-07-13
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2.
- CVE-2026-6373MEDIUMCVSS 6.5EG 6.52026-08-10
Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprinting. This issue affects WAH7601: through 20072026.
- CVE-2026-65458MEDIUMCVSS 4.3EG 4.32026-07-23
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby Polylang Pro allows Retrieve Embedded Sensitive Data. This issue affects Polylang: through 3.8.5; Polylang Pro: through…
- CVE-2026-65474MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
- CVE-2026-65490MEDIUMCVSS 5.3EG 5.32026-07-23
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in John-Michael L'Allier Create mediavine-create allows Retrieve Embedded Sensitive Data.This issue affects Create: from n/a through 2.6.0.
- CVE-2026-65498MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.
- CVE-2026-65505MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
- CVE-2026-65521MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.
- CVE-2026-65535MEDIUMCVSS 4.3EG 4.32026-07-23
Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
- CVE-2026-65564MEDIUMCVSS 5.3EG 5.32026-07-27
Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.
- CVE-2026-66438MEDIUMCVSS 5.3EG 5.32026-07-27
Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.
- CVE-2026-66444MEDIUMCVSS 6.5EG 6.52026-08-13
Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.
- CVE-2026-66462HIGHCVSS 7.5EG 7.52026-08-13
Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.
- CVE-2026-66840HIGHCVSS 7.5EG 7.52026-09-04
XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.
- CVE-2026-67267MEDIUMCVSS 5.5EG 5.52026-08-19
Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerabili…
- CVE-2026-68842MEDIUMCVSS 5.5EG 5.52026-09-08
Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.
- CVE-2026-69127MEDIUMCVSS 6.9EG 6.92026-08-07
Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthen…
- CVE-2026-69315MEDIUMCVSS 5.5EG 5.52026-09-08
Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information locally.
- CVE-2026-69339MEDIUMCVSS 5.5EG 5.52026-09-08
Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.
- CVE-2026-69406MEDIUMCVSS 5.5EG 5.52026-09-08
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally.
- CVE-2026-69723MEDIUMCVSS 5.7EG 5.72026-09-08
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a network.
- CVE-2026-69832MEDIUMCVSS 4.7EG 5.62026-09-08
Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.
- CVE-2026-71330HIGHCVSS 7.5EG 7.52026-09-08
Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.
- CVE-2026-74007MEDIUMCVSS 5.3EG 5.32026-08-18
Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.
- CVE-2026-75928MEDIUMCVSS 5.3EG 5.32026-08-21
The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a remote, unauthenticated attacker to read information about other users. Fixed February 2026.
- CVE-2026-76968MEDIUMCVSS 6.5EG 6.52026-09-08
SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, …
- CVE-2026-78268HIGHCVSS 7.5EG 7.52026-08-24
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.
- CVE-2026-7864MEDIUMCVSS 6.9EG 6.92026-05-08
SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information.
- CVE-2026-80118HIGHCVSS 7.1EG 7.12026-09-04
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users throu…
- CVE-2026-80119HIGHCVSS 7.8EG 7.82026-09-04
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dum…
Map vulnerabilities like CWE-497 to your infrastructure
EchelonGraph correlates every CVE — across CWE-497 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →