Weaknesses of type CWE-200

4,974 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-77773MEDIUMSocial Contact Form (FormyChat) < 2.15.8 - Unauthenticated Gravity Forms Entry Disclosure via formychat_get_gf_entryEPSS 0.3%CVE-2026-58149MEDIUMJoomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0EPSS 0.3%CVE-2026-78151MEDIUMFormLayer < 1.0.9 - Unauthenticated Form Configuration Disclosure via Form Submission ResponseEPSS 0.3%CVE-2026-16612MEDIUMFiboSearch < 1.34.1 - Unauthenticated Password-Protected Product Information DisclosureEPSS 0.3%CVE-2026-86449MEDIUMLearnPress < 4.4.7 - Unauthenticated Unpublished Course Disclosure via REST APIEPSS 0.3%CVE-2024-10365MEDIUMThe Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.0.3 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplatesEPSS 0.3%CVE-2026-82124MEDIUMSchema & Structured Data for WP & AMP < 1.66 - Unauthenticated Password-Protected Post Content Disclosure via JSON-LD Schema OutputEPSS 0.3%CVE-2026-88995MEDIUMBookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability CheckEPSS 0.3%CVE-2026-77754MEDIUMKirki < 6.0.14 - Unauthenticated User and Comment Author Email Disclosure via kirki_get_apisEPSS 0.3%CVE-2026-87896MEDIUMRox Appointment Booking < 1.2.8 - Unauthenticated Staff PII Disclosure via Agent REST RouteEPSS 0.3%CVE-2026-77758MEDIUMStripe Payment Forms by WP Full Pay < 8.5.1 - Unauthenticated Customer Portal Subscription and Billing Data Disclosure via Unconfirmed SessionEPSS 0.3%CVE-2026-14240MEDIUMTourmaster < 5.4.9 - Unauthenticated Sensitive Data Disclosure via Order ExportEPSS 0.3%CVE-2026-19073MEDIUMOrder Sync with Zendesk for WooCommerce < 2.2.3 - Unauthenticated Customer Order Data DisclosureEPSS 0.3%CVE-2026-11351MEDIUMShinyStat Analytics < 1.0.17 - Unauthenticated Non-Published Product Information DisclosureEPSS 0.3%CVE-2026-81022MEDIUMSupportCandy 3.3.6 - 3.5.2 - Unauthenticated Ticket Content Disclosure via Auth Code LeakEPSS 0.3%CVE-2026-87916MEDIUMWPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII DisclosureEPSS 0.3%CVE-2026-78125MEDIUMLearnPress – Sepay Payment < 4.0.3 - Unauthenticated Order Status DisclosureEPSS 0.3%CVE-2026-16575MEDIUMDokan < 5.0.14 - Unauthenticated Commission Settings Disclosure via Store Categories REST EndpointEPSS 0.3%CVE-2026-81195MEDIUMMasterStudy LMS < 3.7.46 - Unauthenticated Student Enrollment Disclosure via student-courses REST RouteEPSS 0.3%CVE-2024-23228MEDIUMThis issue was addressed through improved state management. This issue is fixed in iOS 17.3 and iPadOS 17.3. Locked Notes content may have bEPSS 0.3%