Weaknesses of type CWE-201

411 results

Exposição de informações sensíveis em dados transmitidos

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais, chaves) em comunicações que não deveriam conter essas informações. O desenvolvedor inclui acidentalmente ou por falha de lógica dados confidenciais em respostas, logs, cookies ou requisições que podem ser interceptadas ou expostas.

Example

Um sistema de e-commerce retorna a senha do usuário em uma resposta JSON após login, ou inclui o token de autenticação em um parâmetro GET visível na URL, permitindo que seja capturada em logs de servidor ou histórico do navegador.

How to mitigate

Revise todo dado enviado em respostas HTTP, cookies e headers para eliminar informações sensíveis; use variáveis de ambiente para credenciais, nunca as codifique; aplique sanitização antes de escrever em logs; utilize HTTPS obrigatoriamente e tokens seguros com ciclo de vida limitado.

CVE-2026-59519MEDIUMWordPress FormLayer plugin <= 1.0.6 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2026-59511MEDIUMWordPress Exclusive Addons Elementor plugin <= 2.7.9.9 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-55750MEDIUMGitpod Classic Affected by Bitbucket OAuth Token Exposure via Redirect FragmentEPSS 0.3%CVE-2023-38013MEDIUMIBM Cloud Pak System information disclosureEPSS 0.3%CVE-2026-48965MEDIUMWordPress XCloner plugin <= 4.8.6 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-26335MEDIUMDell PowerProtect Cyber Recovery, versions prior to 19.18.0.2, contains an Insertion of Sensitive Information Into Sent Data vulnerability. EPSS 0.3%CVE-2025-48219LOWO2 UK before 2025-05-19 allows subscribers to determine the Cell ID of other subscribers by initiating an IMS (IP Multimedia Subsystem) callEPSS 0.3%CVE-2025-43768MEDIUMLiferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2EPSS 0.3%CVE-2025-49918MEDIUMWordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.2 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-68855MEDIUMWordPress JobBoard Job listing plugin <= 1.2.8 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2026-24565MEDIUMWordPress B Accordion plugin <= 2.0.2 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2026-67425HIGHFlyto2 Core: LLM/API keys leak to an attacker-controlled base_urlEPSS 0.3%CVE-2020-37093HIGHNetis E1+ 1.2.32533 - Unauthenticated WiFi Password LeakEPSS 0.3%CVE-2026-54848HIGHWordPress APIExperts Square for WooCommerce plugin <= 4.7.3 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-68515MEDIUMWordPress WP Booking System plugin <= 2.0.19.12 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-64295MEDIUMWordPress All In One SEO Pack plugin <= 4.8.6.1 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-2615MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.3%CVE-2025-62038MEDIUMWordPress MeetingHub plugin <= 1.23.9 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-7204MEDIUMExposure of password hashes via API responses in ConnectWise PSAEPSS 0.3%CVE-2026-22551MEDIUMIn Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitraryEPSS 0.3%