Falhas do tipo CWE-200

4.942 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2024-25903MEDIUMWordPress Frontend File Manager Plugin plugin <= 22.7 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-24867MEDIUMWordPress WP Stats Manager plugin <= 6.9.4 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-25591MEDIUMWordPress WP Editor plugin <=1.2.7 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-25933MEDIUMWordPress PeproDev Ultimate Invoice plugin <= 1.9.7 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2025-1322MEDIUMWP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Protected Post DisclosureEPSS 0.5%CVE-2026-9153MEDIUMArbitrary File Read in Rapid7 InsightConnect Sed PluginEPSS 0.5%CVE-2022-43889MEDIUMIBM Security Verify Privilege information disclosureEPSS 0.5%CVE-2023-52185MEDIUMWordPress Everest Backup Plugin <= 2.1.9 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2026-45377MEDIUMDecidim: Private exports can be downloaded through reusable linksEPSS 0.5%CVE-2022-32751MEDIUMIBM Security Verify Directory information disclosureEPSS 0.5%CVE-2024-25839HIGHAn issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attackEPSS 0.5%CVE-2024-6554MEDIUMBranda – White Label WordPress, Custom Login Page Customizer <= 3.4.18 - Unauthenticated Full Path DisclosureEPSS 0.5%CVE-2026-49853HIGHTornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClientEPSS 0.5%CVE-2024-0910MEDIUMRestrict for Elementor <= 1.0.7 - Protection Mechanism BypassEPSS 0.5%CVE-2024-5615MEDIUMOpen Graph <= 1.11.2 - Unauthenticated Sensitive Information ExposureEPSS 0.5%CVE-2026-92770HIGHHarbor through 2.15.2 Scanner Credential Disclosure via Query ParameterEPSS 0.5%CVE-2025-63891HIGHInformation Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacEPSS 0.5%CVE-2026-92811HIGHbrowserless 1.44.0 through 2.56.7 File Protocol Restriction BypassEPSS 0.5%CVE-2026-72726MEDIUMDiscourse: Unauthorized eavesdropping on private AI bot conversations.EPSS 0.5%CVE-2023-49762MEDIUMWordPress AppMySite Plugin <= 3.11.0 is vulnerable to Sensitive Data ExposureEPSS 0.5%