Weaknesses of type CWE-200

4,942 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-25903MEDIUMWordPress Frontend File Manager Plugin plugin <= 22.7 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-24867MEDIUMWordPress WP Stats Manager plugin <= 6.9.4 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-25591MEDIUMWordPress WP Editor plugin <=1.2.7 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-25933MEDIUMWordPress PeproDev Ultimate Invoice plugin <= 1.9.7 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2025-1322MEDIUMWP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Protected Post DisclosureEPSS 0.5%CVE-2026-9153MEDIUMArbitrary File Read in Rapid7 InsightConnect Sed PluginEPSS 0.5%CVE-2022-43889MEDIUMIBM Security Verify Privilege information disclosureEPSS 0.5%CVE-2023-52185MEDIUMWordPress Everest Backup Plugin <= 2.1.9 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2026-45377MEDIUMDecidim: Private exports can be downloaded through reusable linksEPSS 0.5%CVE-2022-32751MEDIUMIBM Security Verify Directory information disclosureEPSS 0.5%CVE-2024-25839HIGHAn issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attackEPSS 0.5%CVE-2024-6554MEDIUMBranda – White Label WordPress, Custom Login Page Customizer <= 3.4.18 - Unauthenticated Full Path DisclosureEPSS 0.5%CVE-2026-49853HIGHTornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClientEPSS 0.5%CVE-2024-0910MEDIUMRestrict for Elementor <= 1.0.7 - Protection Mechanism BypassEPSS 0.5%CVE-2024-5615MEDIUMOpen Graph <= 1.11.2 - Unauthenticated Sensitive Information ExposureEPSS 0.5%CVE-2026-92770HIGHHarbor through 2.15.2 Scanner Credential Disclosure via Query ParameterEPSS 0.5%CVE-2025-63891HIGHInformation Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacEPSS 0.5%CVE-2026-92811HIGHbrowserless 1.44.0 through 2.56.7 File Protocol Restriction BypassEPSS 0.5%CVE-2026-72726MEDIUMDiscourse: Unauthorized eavesdropping on private AI bot conversations.EPSS 0.5%CVE-2023-49762MEDIUMWordPress AppMySite Plugin <= 3.11.0 is vulnerable to Sensitive Data ExposureEPSS 0.5%