CWE-200: Information Exposure
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Yearly Trend
Top Affected Vendors
All Information Exposure CVEs (1,079)
OpenClaw personal AI assistant versions before 2026.2.14 could expose sensitive configuration secrets to clients with read-only permissions. The vulne...
Feb 19, 2026A low-privileged user without admin role can access Splunk Monitoring Console endpoints due to improper access control in vulnerable Splunk Enterprise...
Feb 18, 2026This vulnerability in WeKan allows remote attackers to access sensitive information through the Meteor Publication Handler in the cards.js component. ...
Feb 8, 2026The WP Recipe Maker WordPress plugin up to version 10.2.2 contains an information exposure vulnerability where authenticated users with Contributor-le...
Jan 16, 2026The GenerateBlocks WordPress plugin up to version 2.1.2 has an information exposure vulnerability that allows authenticated users with Contributor-lev...
Dec 13, 2025SIMATIC CN 4100 devices expose server information in responses, allowing attackers with network access to gather reconnaissance data. This information...
Dec 9, 2025The Beaver Builder WordPress plugin up to version 2.9.4 contains an information disclosure vulnerability that allows authenticated users with Contribu...
Dec 9, 2025This vulnerability allows low-privileged Splunk users who subscribe to mobile push notifications to receive notification titles and descriptions for r...
Dec 3, 2025This vulnerability allows authenticated users in Search Guard FLX to read documents from data streams without proper authorization when enterprise mod...
Dec 1, 2025This CVE describes an information disclosure vulnerability in nutzam NutzBoot's Ethereum Wallet Handler component. Attackers can remotely exploit this...
Dec 1, 2025This vulnerability in yungifez Skuul School Management System allows remote attackers to access sensitive information through improper handling of ima...
Nov 30, 2025This vulnerability allows any authenticated user in OrangeHRM to download candidate attachments (CVs, documents) without proper authorization checks. ...
Nov 29, 2025OrangeHRM versions 5.0 to 5.7 have an authorization bypass vulnerability in the Recruitment module's interview attachment endpoint. Authenticated ESS-...
Nov 29, 2025This vulnerability allows any authenticated Mattermost user to view team email addresses that should only be visible to Team Admins. The information d...
Nov 27, 2025CVE-2025-13765 allows non-administrative users in Devolutions Server to access email service credentials, potentially exposing sensitive authenticatio...
Nov 27, 2025This CVE describes an information disclosure vulnerability in Apache CloudStack where authorized users could occasionally access data beyond their int...
Nov 27, 2025This vulnerability allows non-admin users in Revive Adserver to view contact names and email addresses of other users due to insecure design policies....
Nov 20, 2025This vulnerability allows read-only administrators in Fortinet FortiADC to access external resource passwords through system logs. It affects multiple...
Nov 18, 2025CVE-2025-64705 is an information disclosure vulnerability in Frappe Learning Management System (LMS) that allows authenticated users to access other s...
Nov 12, 2025This vulnerability in the WP Import β Ultimate CSV XML Importer WordPress plugin allows authenticated attackers with Author-level access or higher t...
Nov 12, 2025An authenticated information disclosure vulnerability in Cisco Unified Intelligence Center allows low-privileged users to access sensitive system info...
Nov 5, 2025This vulnerability in atjiu pybbs allows remote attackers to access sensitive information through an unknown function in UserApiController.java. It af...
Oct 27, 2025This vulnerability allows authenticated attackers with low privileges to read sensitive data from Oracle Life Sciences InForm web servers. It affects ...
Oct 21, 2025This vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows authenticated attackers with low privileges to read sensitive data they shouldn'...
Oct 21, 2025Opencast's editor may publish videos without user notification when users with write access click 'Save & Publish' then select 'Save' instead. This co...
Oct 8, 2025This vulnerability in Portabilis i-Educar allows unauthorized access to class information via the /module/Avaliacao/diarioApi endpoint. Attackers can ...
Sep 17, 2025CVE-2025-55052 is an information disclosure vulnerability that allows unauthorized actors to access sensitive data. This affects systems with the vuln...
Sep 9, 2025This vulnerability allows authenticated backend users in TYPO3 CMS to download CSV files containing data from database tables they shouldn't have acce...
Sep 9, 2025This vulnerability in Jenkins Git client Plugin allows attackers with Overall/Read permission to determine whether specific file paths exist on the Je...
Sep 3, 2025This vulnerability in RemoteClinic allows attackers to remotely exploit the /patients/edit-patient.php endpoint by manipulating the Email parameter, l...
Sep 1, 2025This CVE describes an information disclosure vulnerability in diyhi bbs versions up to 6.8. Attackers can exploit a flaw in the File Compression Handl...
Aug 26, 2025CVE-2025-9240 is an information disclosure vulnerability in elunez eladmin up to version 2.7. The flaw in the /auth/info endpoint allows remote attack...
Aug 20, 2025This vulnerability in Scada-LTS 2.7.8.1 allows information disclosure through the /Scada-LTS/dwr/call/plaincall/WatchListDwr.init.dwr endpoint. Attack...
Aug 19, 2025The EventON Lite WordPress plugin versions up to 2.4.6 contain an information exposure vulnerability that allows unauthenticated attackers to access p...
Aug 15, 2025The B Slider WordPress plugin exposes installed plugin information to authenticated users with subscriber-level access or higher. This vulnerability a...
Aug 15, 2025This vulnerability allows guest users in Apache Superset to access database schema information through the /chart/data endpoint. The API response impr...
Aug 14, 2025This vulnerability in WuKongCRM 11.0 allows remote attackers to obtain sensitive information through error messages exposed by the API Response Handle...
Aug 11, 2025CVE-2025-46388 is an information disclosure vulnerability (CWE-200) that allows unauthorized actors to access sensitive information. This affects syst...
Aug 6, 2025This vulnerability in ChanCMS allows remote attackers to access sensitive information by manipulating accessKey/secretKey parameters in the /sysApp/fi...
Jul 27, 2025This vulnerability allows authenticated SSL-VPN users to access full SSL-VPN configuration settings through specially crafted URLs. It affects FortiOS...
Jun 10, 2025An unauthenticated remote attacker can exploit improper HTTP request sanitization in Cisco Customer Collaboration Platform's web chat interface to red...
Jun 4, 2025This CVE describes an XS-Leaks (Cross-Site Leaks) vulnerability in Firefox and Thunderbird where script elements loading cross-origin resources genera...
May 27, 2025This vulnerability in Summer Pearl Group Vacation Rental Management Platform allows remote attackers to obtain sensitive information through improper ...
May 26, 2025This vulnerability in D-Link DI-7003GV2 routers allows attackers on the local network to access sensitive information through the HTTP endpoint. The i...
May 19, 2025This vulnerability in DΓgitro NGC Explorer 3.44.15 exposes password fields on configuration pages without proper masking, allowing shoulder surfing o...
May 11, 2025This vulnerability in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 7 allows remote attackers to access sensitive informatio...
May 5, 2025This vulnerability in paicoding 1.0.3 allows unauthorized users to view other users' browsing history through the /user/home endpoint. Attackers can r...
Apr 27, 2025This vulnerability in Tempo Operator allows users with full namespace access to extract ServiceAccount tokens and use them to query Kubernetes API per...
Apr 2, 2025This vulnerability in the WidgetKit plugin for WordPress allows authenticated users with Contributor-level access or higher to view sensitive template...
Mar 8, 2025The GenerateBlocks WordPress plugin exposes sensitive content from private, draft, and scheduled posts/pages through the 'get_image_description' funct...
Mar 1, 2025About Information Exposure (CWE-200)
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Our database tracks 1,079 CVEs classified as CWE-200, with 96 rated critical and 398 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.6.
External reference: View CWE-200 on MITRE CWE →
Monitor Information Exposure Vulnerabilities
Get alerted when new Information Exposure CVEs affect your infrastructure.
Start Monitoring Free