Fallos del tipo CWE-200

4974 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-11351MEDIUMShinyStat Analytics < 1.0.17 - Unauthenticated Non-Published Product Information DisclosureEPSS 0.3%CVE-2026-13402MEDIUMRoyal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Template DisclosureEPSS 0.3%CVE-2026-86447MEDIUMLearnPress < 4.4.7 - Unauthenticated Student Enrollment Disclosure via load_content_via_ajaxEPSS 0.3%CVE-2026-86445MEDIUMLearnPress < 4.4.7 - Unauthenticated Question Bank Disclosure via load_content_via_ajaxEPSS 0.3%CVE-2024-39807LOWChannel IDs of archived/restored channels leaked via webhook eventsEPSS 0.3%CVE-2026-77754MEDIUMKirki < 6.0.14 - Unauthenticated User and Comment Author Email Disclosure via kirki_get_apisEPSS 0.3%CVE-2026-61392MEDIUMThere is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information EPSS 0.3%CVE-2026-77758MEDIUMStripe Payment Forms by WP Full Pay < 8.5.1 - Unauthenticated Customer Portal Subscription and Billing Data Disclosure via Unconfirmed SessionEPSS 0.3%CVE-2021-27908MEDIUMIn all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user EPSS 0.3%CVE-2026-58149MEDIUMJoomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0EPSS 0.3%CVE-2024-35682MEDIUMWordPress Otter Blocks PRO plugin <= 2.6.11 - Authenticated Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-15103HIGHDVP-12SE11T - Authentication Bypass via Partial Password DisclosureEPSS 0.3%CVE-2024-34754MEDIUMWordPress Contact Form Widget plugin <= 1.3.9 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2024-12340MEDIUMAnimation Addons for Elementor <= 1.1.6 - Authenticated (Contributor+) Sensitive Information Exposure via Content Slider and Tabs Widget Elementor TemplateEPSS 0.3%CVE-2024-9889MEDIUMElementInvader Addons for Elementor <= 1.2.9 - Authenticated (Contributor+) Information ExposureEPSS 0.3%CVE-2024-10352MEDIUMMagical Addons For Elementor <= 1.2.4 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplateEPSS 0.3%CVE-2024-9541MEDIUMNews Kit Elementor Addons <= 1.2.1 - Authenticated (Contributor+) Sensitive Information Exposure via Canvas Menu Elementor TemplateEPSS 0.3%CVE-2024-10319MEDIUM140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.6 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplateEPSS 0.3%CVE-2025-46659HIGHAn issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HTTPS request.EPSS 0.3%CVE-2026-92044HIGHInformation disclosure in the Networking: HTTP componentEPSS 0.3%