CWE-201: Insertion of Sensitive Information Into Sent Data
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
389 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-24477 — AnythingLLM has key leak in `systemSettings.js`
- CVE-2025-62039 — WordPress AI ChatBot with ChatGPT and Content Generator by AYS plugin <= 2.6.6 - Sensitive Data Exposure vulnerability
- CVE-2025-60188 — WordPress Atarim plugin <= 4.2.1 - Sensitive Data Exposure vulnerability
- CVE-2026-47717 — FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations
- CVE-2026-27934 — Discourse leaks private topic title and post excerpt via user action API endpoint
- CVE-2025-49584 — XWiki makes title of inaccessible pages available through the class property values REST API
- CVE-2025-48045 — MICI Network Co. Ltd. NetFax Server Default Administrator Credentials Disclosure
- CVE-2025-11500 — Credentials exposure in tinycontrol devices
- CVE-2025-24858 — Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server
- CVE-2025-66566 — yawkat LZ4 Java has a possible information leak in Java safe decompressor
- CVE-2025-9958 — Insertion of Sensitive Information Into Sent Data in GitLab
- CVE-2026-39912 — v2board / Xboard Authentication Token Exposure via loginWithMailLink
- CVE-2026-4035 — Environment Variable Resolution Vulnerability in mlflow/mlflow
- CVE-2026-13380 — VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses
- CVE-2025-68033 — WordPress Custom Related Posts plugin <= 1.8.0 - Sensitive Data Exposure vulnerability
- CVE-2025-59010 — WordPress Permalink Manager Lite Plugin <= 2.5.1.3 - Sensitive Data Exposure Vulnerability
- CVE-2025-48331 — WordPress WooCommerce Orders & Customers Exporter <= 5.0 - Sensitive Data Exposure Vulnerability
- CVE-2025-47444 — WordPress GiveWP Plugin < 4.6.1 is vulnerable to Sensitive Data (PII) Exposure
- CVE-2025-32635 — WordPress Hive Support plugin <= 1.2.2 - Sensitive Data Exposure vulnerability
- CVE-2025-32594 — WordPress Simple WP Events plugin <= 1.8.17 - Sensitive Data Exposure vulnerability
Recently published
- CVE-2026-86505 — In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace
- CVE-2026-86497 — In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administra
- CVE-2026-85307 — WordPress KP Agent Ready plugin < 1.2.08 - Sensitive Data Exposure vulnerability
- CVE-2026-77123 — Nexus Repository 3 - Webhook Secret Disclosure via Capability Read API
- CVE-2026-81162 — DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - Information Disclosure - SA-CONTRIB-2026-112
- CVE-2026-81280 — WordPress Print Barcode Labels for your WooCommerce products/orders plugin <= 4.0.0 - Sensitive Data Exposure vulnerability
- CVE-2026-55553 — urllib: Cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage
- CVE-2026-66585 — WordPress WP Cafe Pro plugin < 3.0.15 - Sensitive Data Exposure vulnerability
- CVE-2026-59809 — SiYuan before v3.8.0 Secret Exfiltration via http_request URL
- CVE-2026-63481 — Hurl: Cookies in Cookies section leak when redirecting to a different host
- CVE-2026-75953 — Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3
- CVE-2026-73386 — WordPress Track Geolocation Of Users Using Contact Form 7 plugin <= 3.0.2 - Sensitive Data Exposure vulnerability
- CVE-2026-73384 — WordPress Pay with Contact Form 7 plugin <= 1.0.4 - Sensitive Data Exposure vulnerability
- CVE-2026-74008 — WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.22 - Sensitive Data Exposure vulnerability
- CVE-2026-66463 — WordPress iCARRY plugin <= 2.9 - Sensitive Data Exposure vulnerability
- CVE-2026-66443 — WordPress REST API Log plugin <= 1.7.1 - Sensitive Data Exposure vulnerability
- CVE-2026-28174 — WordPress WP Event SOlution plugin <= 4.1.18 - Sensitive Data Exposure vulnerability
- CVE-2026-47717 — FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations
- CVE-2026-64652 — GitHub CLI: Partial token disclosure in `gh auth status` output
- CVE-2026-66696 — WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.8 - Sensitive Data Exposure vulnerability
More specific weaknesses
- CWE-598 — Use of HTTP Request With Sensitive Query String