CWE-201
363 CVEs • Abstraction: Base
Insertion of Sensitive Information Into Sent Data
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
CVEs (363)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a thr...Show more |
Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions. |
Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions. |
In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a maliciou...Show more |
Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation & Chat Widget <= 4.2.3 versions. |
Unauthenticated Sensitive Data Exposure in Bricksforge <= 3.1.8.4 versions. |
An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could obtain privilege information by using the co...Show more |
Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded Sensitive Data.
This issue affects Widget Options: from n/a through 4.0.1. |
Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions. |
Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions. |
Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions. |
Subscriber Sensitive Data Exposure in Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons <= 1.4.8 versions. |
Subscriber Sensitive Data Exposure in XCloner <= 4.8.6 versions. |
Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions. |
Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions. |
Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions. |
Unauthenticated Sensitive Data Exposure in Backup Migration <= 2.1.1 versions. |
Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data.
This issue affects GetPaid: from n/a through 2.8.49. |
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, which allows authenticated users with the {{manage_secure_connections}} pe...Show more |
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct r...Show more |