CWE-201: CWE-201
Yearly Trend
Top Affected Vendors
All CWE-201 CVEs (146)
This vulnerability in HotCRP conference review software allows authors with at least one submission to download any documents (PDFs, attachments) from...
Jan 19, 2026This vulnerability in Mastodon allows any registered local user to access lists of severed relationships (lost followers/followed users) from moderati...
Jan 8, 2026This vulnerability in the weDevs WP Project Manager WordPress plugin allows attackers to retrieve embedded sensitive data from the plugin's sent data....
Dec 30, 2025This vulnerability in All In One SEO Pack WordPress plugin allows attackers to retrieve embedded sensitive data through information insertion in sent ...
Dec 18, 2025This vulnerability in Apache Airflow allows authenticated users with UI access to view secret values in rendered templates due to improper redaction. ...
Dec 15, 2025This vulnerability in Directus allows authenticated users with read permissions to detect matches in concealed/sensitive fields through search functio...
Nov 13, 2025This vulnerability in Sovlix MeetingHub WordPress plugin allows attackers to retrieve embedded sensitive data from the application. It affects Meeting...
Nov 6, 2025This vulnerability in Liferay Portal and DXP allows unauthorized actors to access sensitive user data through Freemarker templates. It affects multipl...
Oct 3, 2025This vulnerability allows remote authenticated users to view password reminder answers through audit event logs in affected Liferay versions. This aff...
Sep 22, 2025ArgusTech BILGER versions before 2.4.6 contain an information disclosure vulnerability where sensitive data can be inserted into sent messages. Attack...
Sep 16, 2025This vulnerability in the Simple Price Calculator WordPress plugin allows attackers to retrieve embedded sensitive data through information disclosure...
Sep 5, 2025This vulnerability in Gitpod's Bitbucket OAuth integration allowed attackers to craft malicious links that could expose valid Bitbucket access tokens ...
Aug 29, 2025This vulnerability in Crocoblock JetMenu WordPress plugin allows attackers to retrieve embedded sensitive data through information disclosure in sent ...
Aug 20, 2025This vulnerability in Crocoblock JetBlocks For Elementor WordPress plugin allows attackers to retrieve embedded sensitive data through information dis...
Aug 20, 2025This vulnerability in Crocoblock JetTricks WordPress plugin allows attackers to retrieve embedded sensitive data through information disclosure in sen...
Aug 20, 2025This vulnerability in Crocoblock's JetPopup WordPress plugin allows attackers to retrieve embedded sensitive data through information insertion in sen...
Aug 20, 2025This vulnerability in Crocoblock JetWooBuilder WordPress plugin allows attackers to retrieve embedded sensitive data through insertion of information ...
Aug 20, 2025This vulnerability in Crocoblock JetElements For Elementor WordPress plugin allows attackers to retrieve embedded sensitive data from the plugin's com...
Aug 20, 2025CVE-2025-53985 is a sensitive data exposure vulnerability in the Crocoblock JetTabs WordPress plugin that allows attackers to retrieve embedded sensit...
Aug 20, 2025This vulnerability in Crocoblock JetEngine WordPress plugin allows attackers to retrieve embedded sensitive data that should not be exposed. It affect...
Aug 20, 2025This vulnerability in the SureDash WordPress plugin allows attackers to retrieve embedded sensitive data through information insertion into sent data....
Aug 14, 2025This vulnerability in WP Mailster WordPress plugin exposes sensitive embedded data in sent emails. Attackers can retrieve confidential information tha...
Feb 14, 2025This vulnerability in GREYS Korea for WooCommerce WordPress plugin exposes sensitive embedded data through sent information. Attackers can retrieve co...
Feb 3, 2025This vulnerability in UkrSolution Barcode Generator for WooCommerce exposes sensitive data embedded in barcodes to unauthorized users. Attackers can r...
Jan 31, 2025The PostBox WordPress plugin versions up to 1.0.4 contain a vulnerability where sensitive information is embedded in sent data via wpdebuglog function...
Dec 13, 2024CVE-2025-47775 is a vulnerability in Bullfrog GitHub Action versions before 0.8.4 where using TCP breaks network traffic blocking, allowing DNS exfilt...
May 14, 2025This vulnerability in the JobBoard Job Listing WordPress plugin exposes sensitive embedded data through sent information. Attackers can retrieve confi...
Feb 20, 2026This vulnerability in VikBooking Hotel Booking Engine & PMS WordPress plugin allows attackers to retrieve embedded sensitive data through insertion of...
Dec 18, 2025The Black Rider WordPress theme versions up to 1.2.3 contains a vulnerability where sensitive information is embedded in sent data, allowing attackers...
Dec 31, 2025The WPCenter eRoom Zoom Meetings Webinar WordPress plugin (versions up to and including 1.5.6) contains a vulnerability where sensitive information is...
Dec 18, 2025This vulnerability in ShopMagic for WooCommerce allows attackers to retrieve embedded sensitive data from the plugin's sent communications. It affects...
Oct 22, 2025Dell PowerProtect Cyber Recovery versions before 19.18.0.2 expose sensitive information in sent data. A high-privileged remote attacker can exploit th...
Apr 11, 2025Coolify versions up to v4.0.0-beta.420.8 have an API vulnerability that allows authenticated team members to access other users' email change verifica...
Jan 5, 2026Pomerium versions before 0.26.1 expose OAuth2 access and ID tokens on the user info page, allowing potential token theft. This affects organizations u...
Jul 2, 2024This vulnerability in Windows Speech allows an authorized attacker to extract sensitive information from local system memory. It affects Windows syste...
Nov 11, 2025This vulnerability allows attackers to retrieve embedded sensitive data from the CRM Perks Integration for Contact Form 7 HubSpot WordPress plugin. It...
Jan 23, 2026This vulnerability in the Advanced WooCommerce Product Sales Reporting WordPress plugin exposes sensitive data embedded in sent reports. Attackers can...
Feb 3, 2026This vulnerability in the Contact Form 7 GetResponse Extension WordPress plugin allows attackers to retrieve embedded sensitive data from form submiss...
Jan 23, 2026This vulnerability in the Varnish/Nginx Proxy Caching WordPress plugin allows attackers to retrieve sensitive information embedded in cached data. It ...
Dec 31, 2025The Efí Bank Gerencianet Oficial WordPress plugin (versions up to 3.1.3) contains a vulnerability where sensitive information is embedded in sent dat...
Dec 31, 2025The Terms descriptions WordPress plugin versions up to 3.4.9 contains a vulnerability where sensitive information is embedded in sent data, allowing a...
Dec 31, 2025This vulnerability in ScreenConnect's Certificate Signing Extension could expose encrypted Azure Key Vault configuration values to unauthenticated use...
Dec 18, 2025This vulnerability in the Ultimate Auction WordPress plugin exposes sensitive embedded data through sent information. Attackers can retrieve confident...
Dec 16, 2025This vulnerability in the WordPress Fix Media Library plugin allows attackers to retrieve embedded sensitive data from media files. It affects WordPre...
Dec 16, 2025This vulnerability in the auxin-elements WordPress plugin allows attackers to retrieve embedded sensitive data through shortcodes. It affects all Word...
Dec 9, 2025This vulnerability in WP EasyCart WordPress plugin allows attackers to retrieve embedded sensitive data from the plugin's responses. It affects all Wo...
Dec 9, 2025Apache OpenOffice versions through 4.1.15 have an authorization vulnerability where specially crafted documents can automatically load external links ...
Nov 12, 2025This vulnerability in the ACF to REST API WordPress plugin exposes sensitive data embedded in Advanced Custom Fields through the REST API. Attackers c...
Oct 27, 2025This vulnerability in the WordPress Easy Post Submission plugin allows attackers to retrieve embedded sensitive data from submitted posts. It affects ...
Oct 22, 2025This vulnerability allows unauthenticated remote attackers to access undisclosed endpoints containing static non-sensitive information through the BIG...
Oct 15, 2025About CWE-201 (CWE-201)
Our database tracks 146 CVEs classified as CWE-201, with 5 rated critical and 40 rated high severity. The average CVSS score for CWE-201 vulnerabilities is 6.2.
External reference: View CWE-201 on MITRE CWE →
Monitor CWE-201 Vulnerabilities
Get alerted when new CWE-201 CVEs affect your infrastructure.
Start Monitoring Free