Fallos del tipo CWE-201

411 resultados

Inserção de informações sensíveis em dados enviados

A aplicação inclui dados sensíveis (senhas, tokens, chaves, PII) em comunicações que não deveriam contê-los — logs, requisições HTTP, mensagens de erro, caches ou tráfego de rede. O risco é esses dados serem interceptados, armazenados ou expostos em canais menos protegidos.

Ejemplo

Um sistema registra credenciais de banco de dados completas em logs de debug que ficam acessíveis a analistas, ou uma API retorna o token de autenticação do usuário em resposta de erro exibida ao cliente. Outro caso comum: enviar senhas em parâmetros de URL (no histórico do navegador e logs de servidor).

Cómo mitigar

Identifique quais dados são sensíveis e nunca os inclua em logs, mensagens de erro, caches ou respostas da API. Use máscara (ex: exibir apenas últimos 4 dígitos) quando necessário exibir, e sanitize outputs antes de enviar ao cliente. Revise regularmente logs e históricos de requisição.

CVE-2026-59519MEDIUMWordPress FormLayer plugin <= 1.0.6 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2026-59511MEDIUMWordPress Exclusive Addons Elementor plugin <= 2.7.9.9 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-55750MEDIUMGitpod Classic Affected by Bitbucket OAuth Token Exposure via Redirect FragmentEPSS 0.3%CVE-2023-38013MEDIUMIBM Cloud Pak System information disclosureEPSS 0.3%CVE-2026-48965MEDIUMWordPress XCloner plugin <= 4.8.6 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-26335MEDIUMDell PowerProtect Cyber Recovery, versions prior to 19.18.0.2, contains an Insertion of Sensitive Information Into Sent Data vulnerability. EPSS 0.3%CVE-2025-48219LOWO2 UK before 2025-05-19 allows subscribers to determine the Cell ID of other subscribers by initiating an IMS (IP Multimedia Subsystem) callEPSS 0.3%CVE-2025-43768MEDIUMLiferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2EPSS 0.3%CVE-2025-49918MEDIUMWordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.2 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-68855MEDIUMWordPress JobBoard Job listing plugin <= 1.2.8 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2026-24565MEDIUMWordPress B Accordion plugin <= 2.0.2 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2026-67425HIGHFlyto2 Core: LLM/API keys leak to an attacker-controlled base_urlEPSS 0.3%CVE-2020-37093HIGHNetis E1+ 1.2.32533 - Unauthenticated WiFi Password LeakEPSS 0.3%CVE-2026-54848HIGHWordPress APIExperts Square for WooCommerce plugin <= 4.7.3 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-68515MEDIUMWordPress WP Booking System plugin <= 2.0.19.12 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-64295MEDIUMWordPress All In One SEO Pack plugin <= 4.8.6.1 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-2615MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.3%CVE-2025-62038MEDIUMWordPress MeetingHub plugin <= 1.23.9 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-7204MEDIUMExposure of password hashes via API responses in ConnectWise PSAEPSS 0.3%CVE-2026-22551MEDIUMIn Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitraryEPSS 0.3%