Weaknesses of type CWE-200

4,951 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-84179MEDIUMApache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology PageEPSS 0.4%CVE-2026-32002MEDIUMOpenClaw < 2026.2.23 - Sandbox Boundary Bypass via Image Tool workspaceOnly BypassEPSS 0.4%CVE-2024-47779HIGHElement Web vulnerable to potential exposure of access token via authenticated mediaEPSS 0.4%CVE-2026-14839HIGHMapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content DisclosureEPSS 0.4%CVE-2026-16611HIGHProduct Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration DisclosureEPSS 0.4%CVE-2026-92404HIGHMgoSync 2.1.5 - 2.1.6 - Unauthenticated WooCommerce API Credential DisclosureEPSS 0.4%CVE-2026-18049HIGHWP Photo Album Plus < 9.2.07.002 - Unauthenticated Option Disclosure via gettogoEPSS 0.4%CVE-2026-16253HIGHTotal Upkeep < 1.17.3 - Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secretEPSS 0.4%CVE-2026-17541HIGHBit File Manager < 6.9.1 - Unauthenticated File Activity Log DisclosureEPSS 0.4%CVE-2026-77007HIGHHEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated BigBlueButton API Secret DisclosureEPSS 0.4%CVE-2026-14319HIGHGiveWP < 4.16.3 - Unauthenticated Recurring Donor Information DisclosureEPSS 0.4%CVE-2026-17022HIGHSalon Booking System – Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking WizardEPSS 0.4%CVE-2026-14925HIGHImport WP < 2.14.23 - Unauthenticated Sensitive Information Exposure via Export File DownloadEPSS 0.4%CVE-2026-16604HIGHContent Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disclosure via Content-Lock Block data-content AttributeEPSS 0.4%CVE-2025-0224MEDIUMProvision-ISR SH-4050A-2 server.js information disclosureEPSS 0.4%CVE-2026-19717HIGHCatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure via REST APIEPSS 0.4%CVE-2026-18946HIGHContact Form to Any API < 3.0.7 - Unauthenticated Sensitive File Disclosure via Predictable FilenameEPSS 0.4%CVE-2026-14206HIGHHT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data DisclosureEPSS 0.4%CVE-2026-16602HIGHContent Protector (Passster) < 4.3.6 - Unauthenticated Non-Public Post Content Disclosure via Captcha REST EndpointEPSS 0.4%CVE-2026-18470HIGHLogin & Register Forms < 4.0.2 - Unauthenticated Registered User Email Address Disclosure via Lost Password ResponseEPSS 0.4%