Weaknesses of type CWE-497

402 results

Divulgação de Informações Sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, dados pessoais) através de canais inseguros ou em contextos onde não deveria — logs, mensagens de erro, cache, memória ou tráfego de rede desencriptado. O risco é um atacante interceptar ou acessar esses dados e comprometer contas, sistemas ou privacidade.

Example

Uma API retorna a senha do usuário em texto plano dentro de um JSON de resposta de erro; um servidor expõe tokens de autenticação em arquivos de log acessíveis publicamente; uma página web carrega chaves de API dentro de variáveis JavaScript visíveis no código-fonte.

How to mitigate

Nunca exponha dados sensíveis em logs, mensagens de erro visíveis ao usuário ou código cliente. Criptografe dados em trânsito (HTTPS/TLS), use variáveis de ambiente ou vaults para armazenar credenciais, e revise regularmente o que é registrado ou retornado em respostas. Implemente redação de dados sensíveis (masking) em logs e erros.

CVE-2026-65535MEDIUMWordPress TinyMCE Templates plugin <= 4.8.1 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-13691HIGHDataStage on Cloud Pak for Data is vulnerable to sensitive information leaks due to HTTP processingEPSS 0.3%CVE-2026-65458MEDIUMWordPress Polylang and Polylang Pro plugins <= 3.8.5 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-57916MEDIUMWordPress WP System Information Plugin <= 1.5 - Sensitive Data Exposure VulnerabilityEPSS 0.3%CVE-2025-39394MEDIUMWordPress AnalyticsWP plugin <= 2.1.2 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-57937MEDIUMWordPress WPeMatico RSS Feed Fetcher Plugin <= 2.8.10 - Sensitive Data Exposure VulnerabilityEPSS 0.3%CVE-2026-57664MEDIUMWordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.1.6 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-0278MEDIUMAn internal path disclosure vulnerability affects HCL TravelerEPSS 0.3%CVE-2026-59548HIGHWordPress Byteflows Travel & Hotel Booking plugin <= 1.0.0 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-27149MEDIUMZulip exports can leak private dataEPSS 0.3%CVE-2026-49066HIGHWordPress Conekta Payment Gateway plugin <= 6.0.0 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2024-1809MEDIUMAnalytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) <= 5.2.3 - Missing AuthorizationEPSS 0.3%CVE-2026-69127MEDIUMKirby: System path exposure from error messages in the REST APIEPSS 0.3%CVE-2025-68988MEDIUMWordPress E-Invoice App Malaysia plugin <= 1.3.0 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-32228MEDIUMWordPress Ai Image Alt Text Generator for WP plugin <= 1.1.9 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-9364HIGHRockwell Automation FactoryTalk® Analytics™ LogixAI® Exposed Redis DBEPSS 0.3%CVE-2026-17595MEDIUMNexus Repository 3 - JEXL Content Selector Sandbox Property-Read BypassEPSS 0.3%CVE-2025-62735MEDIUMWordPress User Spam Remover plugin <= 1.1 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-63009MEDIUMWordPress WP Google Analytics Events plugin <= 2.8.2 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-67567MEDIUMWordPress Sober theme <= 3.5.11 - Sensitive Data Exposure vulnerabilityEPSS 0.3%