Weaknesses of type CWE-201

411 results

Exposição de informações sensíveis em dados transmitidos

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais, chaves) em comunicações que não deveriam conter essas informações. O desenvolvedor inclui acidentalmente ou por falha de lógica dados confidenciais em respostas, logs, cookies ou requisições que podem ser interceptadas ou expostas.

Example

Um sistema de e-commerce retorna a senha do usuário em uma resposta JSON após login, ou inclui o token de autenticação em um parâmetro GET visível na URL, permitindo que seja capturada em logs de servidor ou histórico do navegador.

How to mitigate

Revise todo dado enviado em respostas HTTP, cookies e headers para eliminar informações sensíveis; use variáveis de ambiente para credenciais, nunca as codifique; aplique sanitização antes de escrever em logs; utilize HTTPS obrigatoriamente e tokens seguros com ciclo de vida limitado.

CVE-2025-47541HIGHWordPress Mail Mint plugin <= 1.17.7 - Sensitive Data Exposure VulnerabilityEPSS 0.5%CVE-2023-3399HIGHInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2025-31134MEDIUMFreshRSS vulnerable to directory enumeration via ext.phpEPSS 0.4%CVE-2024-49235HIGHWordPress Contact Forms, Live Support, CRM, Video Messages plugin <= 1.10.2 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-49584HIGHXWiki makes title of inaccessible pages available through the class property values REST APIEPSS 0.4%CVE-2026-41181MEDIUMTraefik: Errors middleware forwards Authorization and Cookie headers to separate error page serviceEPSS 0.4%CVE-2024-26270MEDIUMThe Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 EPSS 0.4%CVE-2025-22303MEDIUMWordPress WP Mailster plugin <= 1.8.17.0 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-25150MEDIUMInformation disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and LiferayEPSS 0.4%CVE-2026-13437MEDIUMInsertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticatEPSS 0.4%CVE-2026-42997HIGHAn issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be senEPSS 0.4%CVE-2026-54171MEDIUMExcon: redact additional sensitive/risky headers when following redirectsEPSS 0.4%CVE-2025-48749CRITICALNetwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent DaEPSS 0.4%CVE-2025-48934MEDIUMDeno.env.toObject() ignores the variables listed in --deny-env and returns all environment variablesEPSS 0.4%CVE-2024-38787HIGHWordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerabilityEPSS 0.4%CVE-2026-6267HIGHInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.4%CVE-2025-64502MEDIUMParse Server allows public `explain` queries which may expose sensitive database performance information and schema detailsEPSS 0.4%CVE-2024-39315MEDIUMPomerium exposed OAuth2 access and ID tokens in user info endpoint responseEPSS 0.4%CVE-2026-7189HIGHSensitive Data Exposure in Proliz's OBSEPSS 0.4%CVE-2026-7488HIGHSensitive Data Exposure in IKAS Technologies' E-CommerceEPSS 0.4%