CWE-201: CWE-201

146
Total CVEs
5
Critical
40
High
6.2
Avg CVSS

Yearly Trend

2026
22
2025
105
2024
13
2023
2
2021
2

Top Affected Vendors

1 Cisco 5
2 Liferay 4
3 Gitlab 3
4 Apache 3
5 Xwiki 2
6 F5 2
7 Wpmailster 2
8 File Entity Project 1
9 Connectwise 1
10 Pomerium 1

All CWE-201 CVEs (146)

CVE-2020-26085
9.9

This critical vulnerability in Cisco Jabber allows attackers to execute arbitrary programs with elevated privileges or access sensitive information. I...

Jan 7, 2021
CVE-2020-27133
9.9

CVE-2020-27133 is a critical vulnerability in Cisco Jabber that allows attackers to execute arbitrary code with elevated privileges or access sensitiv...

Dec 11, 2020
CVE-2020-27127
9.9

This critical vulnerability in Cisco Jabber allows attackers to execute arbitrary code with elevated privileges or access sensitive information. It af...

Dec 11, 2020
CVE-2025-48749
9.1

Netwrix Directory Manager (formerly Imanami GroupID) versions 11.0.0.0 and earlier, and versions after 11.1.25134.03, expose sensitive information in ...

May 28, 2025
CVE-2023-48240
9.0

This vulnerability in XWiki Platform allows attackers to steal login and session cookies via image embedding in rendered diffs, enabling user imperson...

Nov 20, 2023
CVE-2023-3399
8.5

This vulnerability allows unauthorized project or group members in GitLab EE to read CI/CD variables through custom project templates. It affects all ...

Nov 6, 2023
CVE-2025-58098
8.3

This vulnerability in Apache HTTP Server allows remote code execution when Server Side Includes (SSI) is enabled with mod_cgid. Attackers can inject s...

Dec 5, 2025
CVE-2025-3529
8.2

The WordPress Simple Shopping Cart plugin has a vulnerability that allows unauthenticated attackers to access sensitive information and download paid ...

Apr 23, 2025
CVE-2024-3502
8.1

This vulnerability exposes account recovery hashes through API endpoints in lunary-ai/lunary, allowing authenticated users to access sensitive informa...

Nov 14, 2024
CVE-2024-8890
8.0

CVE-2024-8890 allows attackers on the same network as vulnerable CIRCUTOR Q-SMT devices to intercept credentials and hijack sessions because the devic...

Sep 18, 2024
CVE-2021-23019
7.8

CVE-2021-23019 exposes NGINX Controller administrator passwords in the systemd.txt file within support packages. This allows attackers with access to ...

Jun 1, 2021
CVE-2025-43768
7.7

This vulnerability allows authenticated users without specific permissions to access sensitive information of admin users via JSONWS APIs in Liferay P...

Aug 23, 2025
CVE-2024-7872
7.6

ExtremePACS Extreme XDS before version 3933 contains a vulnerability where sensitive information is improperly embedded in sent data, allowing attacke...

Mar 6, 2025
CVE-2026-27516
7.5

Binardat 10G08-0800GSM network switches expose administrative passwords in plaintext within the web interface and HTTP responses, allowing attackers t...

Feb 24, 2026
CVE-2020-37150
7.5

This vulnerability allows unauthenticated attackers to access the /wizard_reboot.asp page on Edimax EW-7438RPn-v3 Mini range extenders, which disclose...

Feb 5, 2026
CVE-2026-24430
7.5

This vulnerability exposes administrative credentials in plaintext within HTTP responses from the Tenda W30E V2 router's maintenance interface. Attack...

Jan 26, 2026
CVE-2025-68035
7.5

This vulnerability in the Tabby Checkout WordPress plugin exposes sensitive data embedded in sent information, allowing attackers to retrieve confiden...

Jan 22, 2026
CVE-2025-63019
7.5

This vulnerability in the WordPress Cookies and Content Security Policy plugin allows attackers to retrieve embedded sensitive data from sent informat...

Jan 22, 2026
CVE-2025-67931
7.5

This vulnerability in the BulletProof Security WordPress plugin allows attackers to retrieve embedded sensitive data through information insertion int...

Jan 8, 2026
CVE-2025-68989
7.5

This vulnerability in the Contact Form 7 Extension For Mailchimp WordPress plugin exposes sensitive data embedded in form submissions. Attackers can r...

Dec 30, 2025
CVE-2025-68516
7.5

This vulnerability in the Tablesome WordPress plugin allows attackers to retrieve embedded sensitive data from tables. It affects all WordPress sites ...

Dec 24, 2025
CVE-2025-66116
7.5

This vulnerability in Ultimate Member Widgets for Elementor WordPress plugin allows attackers to retrieve embedded sensitive data from the plugin's wi...

Dec 18, 2025
CVE-2025-64213
7.5

This vulnerability in MasterStudy LMS Pro WordPress plugin allows attackers to retrieve embedded sensitive data from the system. It affects all WordPr...

Dec 18, 2025
CVE-2025-64218
7.5

This vulnerability in the Passster WordPress plugin allows attackers to retrieve embedded sensitive data that should be protected. It affects all Word...

Dec 18, 2025
CVE-2025-62109
7.5

This vulnerability in the INFINITUM FORM Geo Controller WordPress plugin exposes sensitive embedded data through sent information. Attackers can retri...

Dec 9, 2025
CVE-2025-13295
7.5

This vulnerability in Argus Technology Inc.'s BILGER software allows attackers to insert sensitive information into transmitted data by manipulating m...

Dec 2, 2025
CVE-2025-62039
7.5

This vulnerability allows attackers to retrieve embedded sensitive data from the Ays Pro AI ChatBot WordPress plugin. The plugin inadvertently exposes...

Nov 6, 2025
CVE-2025-60188
7.5

This vulnerability in the Atarim Visual Collaboration WordPress plugin allows attackers to retrieve embedded sensitive data from the plugin's sent com...

Nov 6, 2025
CVE-2025-62947
7.5

The Publitio WordPress plugin versions up to 2.2.3 contain a vulnerability that allows attackers to retrieve embedded sensitive data from sent informa...

Oct 27, 2025
CVE-2025-62895
7.5

This vulnerability in the Atarim Visual Collaboration WordPress plugin allows attackers to retrieve embedded sensitive data from the plugin's sent dat...

Oct 27, 2025
CVE-2025-59579
7.5

This vulnerability in the Simple Job Board WordPress plugin allows attackers to retrieve embedded sensitive data from job applications, such as person...

Oct 22, 2025
CVE-2025-47444
7.5

GiveWP WordPress plugin versions before 4.6.1 expose sensitive personal information (PII) in sent data. This vulnerability allows attackers to retriev...

Aug 12, 2025
CVE-2025-49584
7.5

This vulnerability in XWiki allows attackers to access page titles through the REST API without proper authorization. It affects XWiki installations w...

Jun 13, 2025
CVE-2025-48261
7.5

This vulnerability in MultiVendorX WordPress plugin allows attackers to retrieve embedded sensitive data that should not be exposed. It affects all Wo...

Jun 9, 2025
CVE-2025-31134
7.5

FreshRSS versions before 1.26.2 contain an information disclosure vulnerability that allows attackers to check for the existence of specific directori...

Jun 4, 2025
CVE-2025-32635
7.5

The Hive Support WordPress plugin versions up to 1.2.2 contain a vulnerability that allows attackers to retrieve embedded sensitive data through infor...

Apr 17, 2025
CVE-2025-23774
7.5

This vulnerability in the WPDB to Sql WordPress plugin allows attackers to retrieve sensitive embedded data through information disclosure in sent dat...

Jan 22, 2025
CVE-2025-23781
7.5

This vulnerability in the WM Options Import Export WordPress plugin allows attackers to retrieve embedded sensitive data through information insertion...

Jan 22, 2025
CVE-2024-13276
7.5

This vulnerability in Drupal File Entity module allows attackers to access sensitive files through forceful browsing by manipulating URLs. It affects ...

Jan 9, 2025
CVE-2024-56300
7.5

This vulnerability in the WPSpins Post/Page Copying Tool WordPress plugin allows attackers to retrieve embedded sensitive data from posts or pages. It...

Jan 7, 2025
CVE-2024-53804
7.5

This vulnerability in WP Mailster WordPress plugin exposes sensitive data embedded in sent emails or communications. Attackers can retrieve confidenti...

Dec 6, 2024
CVE-2024-49235
7.5

This vulnerability allows attackers to retrieve embedded sensitive data from VideoWhisper's WordPress plugins. It affects all installations using Cont...

Oct 17, 2024
CVE-2023-49261
7.5

This vulnerability exposes the 'tokenKey' value used for user authorization in the HTML source of login pages, allowing attackers to bypass authentica...

Jan 12, 2024
CVE-2024-6586
7.3

Lightdash versions before 0.1027.2 contain a server-side request forgery (SSRF) vulnerability that allows authenticated users (Administrators or Edito...

Aug 30, 2024
CVE-2023-6916
7.2

CVE-2023-6916 is an information disclosure vulnerability where OpenAPI audit logs may contain sensitive data like credentials or tokens. This affects ...

Apr 10, 2024
CVE-2025-7708
6.8

This vulnerability in Atlas Educational Software's K12net allows attackers to manipulate communication channels and insert sensitive information into ...

Feb 9, 2026
CVE-2024-4536
6.8

This vulnerability allows attackers to obtain OAuth2 client secrets from the vault in Eclipse Dataspace Components. It affects users of the EDC Connec...

May 7, 2024
CVE-2026-27465
6.5

This vulnerability in Fleet device management software exposes Google Calendar service account credentials to authenticated low-privilege users. Attac...

Feb 26, 2026
CVE-2026-24565
6.5

This vulnerability in the WordPress B Accordion plugin allows attackers to retrieve embedded sensitive data from the plugin's output. It affects all W...

Jan 23, 2026
CVE-2025-68006
6.5

This vulnerability in the Booking Ultra Pro WordPress plugin exposes sensitive embedded data through sent information. Attackers can retrieve confiden...

Jan 22, 2026

About CWE-201 (CWE-201)

Our database tracks 146 CVEs classified as CWE-201, with 5 rated critical and 40 rated high severity. The average CVSS score for CWE-201 vulnerabilities is 6.2.

External reference: View CWE-201 on MITRE CWE →

Monitor CWE-201 Vulnerabilities

Get alerted when new CWE-201 CVEs affect your infrastructure.

Start Monitoring Free