CWE-497— Exposure of Sensitive System Information to an Unauthorized Control Sphere
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.— MITRE CWE catalog
368 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-497page 8 of 8
- CVE-2026-57753MEDIUMCVSS 5.3EG 5.32026-07-02
Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.
- CVE-2026-59528HIGHCVSS 7.5EG 7.52026-07-27
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
- CVE-2026-59548HIGHCVSS 7.5EG 7.52026-07-27
Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.
- CVE-2026-61945MEDIUMCVSS 6.5EG 6.52026-07-23
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a…
- CVE-2026-61975MEDIUMCVSS 5.3EG 5.32026-07-13
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1.
- CVE-2026-61976MEDIUMCVSS 5.3EG 5.32026-07-13
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through …
- CVE-2026-61977MEDIUMCVSS 5.3EG 5.32026-07-13
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2.
- CVE-2026-65458MEDIUMCVSS 4.3EG 4.32026-07-23
Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions.
- CVE-2026-65474MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
- CVE-2026-65490MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.
- CVE-2026-65498MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.
- CVE-2026-65505MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
- CVE-2026-65521MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.
- CVE-2026-65535MEDIUMCVSS 4.3EG 4.32026-07-23
Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
- CVE-2026-65564MEDIUMCVSS 5.3EG 5.32026-07-27
Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.
- CVE-2026-66438MEDIUMCVSS 5.3EG 5.32026-07-27
Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.
- CVE-2026-7864MEDIUMCVSS 6.9EG 6.92026-05-08
SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information.
- CVE-2026-9307MEDIUMCVSS 6.3EG 6.32026-06-16
A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on…
Map vulnerabilities like CWE-497 to your infrastructure
EchelonGraph correlates every CVE — across CWE-497 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →