CWE-201: CWE-201

146
Total CVEs
5
Critical
40
High
6.2
Avg CVSS

Yearly Trend

2026
22
2025
105
2024
13
2023
2
2021
2

Top Affected Vendors

1 Cisco 5
2 Liferay 4
3 Gitlab 3
4 Apache 3
5 Xwiki 2
6 F5 2
7 Wpmailster 2
8 File Entity Project 1
9 Connectwise 1
10 Pomerium 1

All CWE-201 CVEs (146)

CVE-2026-23878
6.5

This vulnerability in HotCRP conference review software allows authors with at least one submission to download any documents (PDFs, attachments) from...

Jan 19, 2026
CVE-2026-22246
6.5

This vulnerability in Mastodon allows any registered local user to access lists of severed relationships (lost followers/followed users) from moderati...

Jan 8, 2026
CVE-2025-68040
6.5

This vulnerability in the weDevs WP Project Manager WordPress plugin allows attackers to retrieve embedded sensitive data from the plugin's sent data....

Dec 30, 2025
CVE-2025-64295
6.5

This vulnerability in All In One SEO Pack WordPress plugin allows attackers to retrieve embedded sensitive data through information insertion in sent ...

Dec 18, 2025
CVE-2025-66388
6.5

This vulnerability in Apache Airflow allows authenticated users with UI access to view secret values in rendered templates due to improper redaction. ...

Dec 15, 2025
CVE-2025-64748
6.5

This vulnerability in Directus allows authenticated users with read permissions to detect matches in concealed/sensitive fields through search functio...

Nov 13, 2025
CVE-2025-62038
6.5

This vulnerability in Sovlix MeetingHub WordPress plugin allows attackers to retrieve embedded sensitive data from the application. It affects Meeting...

Nov 6, 2025
CVE-2025-43825
6.5

This vulnerability in Liferay Portal and DXP allows unauthorized actors to access sensitive user data through Freemarker templates. It affects multipl...

Oct 3, 2025
CVE-2025-43814
6.5

This vulnerability allows remote authenticated users to view password reminder answers through audit event logs in affected Liferay versions. This aff...

Sep 22, 2025
CVE-2025-5519
6.5

ArgusTech BILGER versions before 2.4.6 contain an information disclosure vulnerability where sensitive data can be inserted into sent messages. Attack...

Sep 16, 2025
CVE-2025-58872
6.5

This vulnerability in the Simple Price Calculator WordPress plugin allows attackers to retrieve embedded sensitive data through information disclosure...

Sep 5, 2025
CVE-2025-55750
6.5

This vulnerability in Gitpod's Bitbucket OAuth integration allowed attackers to craft malicious links that could expose valid Bitbucket access tokens ...

Aug 29, 2025
CVE-2025-53987
6.5

This vulnerability in Crocoblock JetMenu WordPress plugin allows attackers to retrieve embedded sensitive data through information disclosure in sent ...

Aug 20, 2025
CVE-2025-53988
6.5

This vulnerability in Crocoblock JetBlocks For Elementor WordPress plugin allows attackers to retrieve embedded sensitive data through information dis...

Aug 20, 2025
CVE-2025-53992
6.5

This vulnerability in Crocoblock JetTricks WordPress plugin allows attackers to retrieve embedded sensitive data through information disclosure in sen...

Aug 20, 2025
CVE-2025-53993
6.5

This vulnerability in Crocoblock's JetPopup WordPress plugin allows attackers to retrieve embedded sensitive data through information insertion in sen...

Aug 20, 2025
CVE-2025-53998
6.5

This vulnerability in Crocoblock JetWooBuilder WordPress plugin allows attackers to retrieve embedded sensitive data through insertion of information ...

Aug 20, 2025
CVE-2025-53983
6.5

This vulnerability in Crocoblock JetElements For Elementor WordPress plugin allows attackers to retrieve embedded sensitive data from the plugin's com...

Aug 20, 2025
CVE-2025-53985
6.5

CVE-2025-53985 is a sensitive data exposure vulnerability in the Crocoblock JetTabs WordPress plugin that allows attackers to retrieve embedded sensit...

Aug 20, 2025
CVE-2025-53196
6.5

This vulnerability in Crocoblock JetEngine WordPress plugin allows attackers to retrieve embedded sensitive data that should not be exposed. It affect...

Aug 20, 2025
CVE-2025-54685
6.5

This vulnerability in the SureDash WordPress plugin allows attackers to retrieve embedded sensitive data through information insertion into sent data....

Aug 14, 2025
CVE-2025-24567
6.5

This vulnerability in WP Mailster WordPress plugin exposes sensitive embedded data in sent emails. Attackers can retrieve confidential information tha...

Feb 14, 2025
CVE-2025-24639
6.5

This vulnerability in GREYS Korea for WooCommerce WordPress plugin exposes sensitive embedded data through sent information. Attackers can retrieve co...

Feb 3, 2025
CVE-2025-24597
6.5

This vulnerability in UkrSolution Barcode Generator for WooCommerce exposes sensitive data embedded in barcodes to unauthorized users. Attackers can r...

Jan 31, 2025
CVE-2024-54309
6.5

The PostBox WordPress plugin versions up to 1.0.4 contain a vulnerability where sensitive information is embedded in sent data via wpdebuglog function...

Dec 13, 2024
CVE-2025-47775
6.2

CVE-2025-47775 is a vulnerability in Bullfrog GitHub Action versions before 0.8.4 where using TCP breaks network traffic blocking, allowing DNS exfilt...

May 14, 2025
CVE-2025-68855
5.9

This vulnerability in the JobBoard Job Listing WordPress plugin exposes sensitive embedded data through sent information. Attackers can retrieve confi...

Feb 20, 2026
CVE-2025-49918
5.9

This vulnerability in VikBooking Hotel Booking Engine & PMS WordPress plugin allows attackers to retrieve embedded sensitive data through insertion of...

Dec 18, 2025
CVE-2025-59003
5.8

The Black Rider WordPress theme versions up to 1.2.3 contains a vulnerability where sensitive information is embedded in sent data, allowing attackers...

Dec 31, 2025
CVE-2025-49919
5.8

The WPCenter eRoom Zoom Meetings Webinar WordPress plugin (versions up to and including 1.5.6) contains a vulnerability where sensitive information is...

Dec 18, 2025
CVE-2025-59578
5.8

This vulnerability in ShopMagic for WooCommerce allows attackers to retrieve embedded sensitive data from the plugin's sent communications. It affects...

Oct 22, 2025
CVE-2025-26335
5.8

Dell PowerProtect Cyber Recovery versions before 19.18.0.2 expose sensitive information in sent data. A high-privileged remote attacker can exploit th...

Apr 11, 2025
CVE-2025-59955
5.7

Coolify versions up to v4.0.0-beta.420.8 have an API vulnerability that allows authenticated team members to access other users' email change verifica...

Jan 5, 2026
CVE-2024-39315
5.7

Pomerium versions before 0.26.1 expose OAuth2 access and ID tokens on the user info page, allowing potential token theft. This affects organizations u...

Jul 2, 2024
CVE-2025-59509
5.5

This vulnerability in Windows Speech allows an authorized attacker to extract sensitive information from local system memory. It affects Windows syste...

Nov 11, 2025
CVE-2026-24559
5.4

This vulnerability allows attackers to retrieve embedded sensitive data from the CRM Perks Integration for Contact Form 7 HubSpot WordPress plugin. It...

Jan 23, 2026
CVE-2026-24992
5.3

This vulnerability in the Advanced WooCommerce Product Sales Reporting WordPress plugin exposes sensitive data embedded in sent reports. Attackers can...

Feb 3, 2026
CVE-2026-24557
5.3

This vulnerability in the Contact Form 7 GetResponse Extension WordPress plugin allows attackers to retrieve embedded sensitive data from form submiss...

Jan 23, 2026
CVE-2025-62126
5.3

This vulnerability in the Varnish/Nginx Proxy Caching WordPress plugin allows attackers to retrieve sensitive information embedded in cached data. It ...

Dec 31, 2025
CVE-2025-59136
5.3

The Efí Bank Gerencianet Oficial WordPress plugin (versions up to 3.1.3) contains a vulnerability where sensitive information is embedded in sent dat...

Dec 31, 2025
CVE-2025-62139
5.3

The Terms descriptions WordPress plugin versions up to 3.4.9 contains a vulnerability where sensitive information is embedded in sent data, allowing a...

Dec 31, 2025
CVE-2025-14823
5.3

This vulnerability in ScreenConnect's Certificate Signing Extension could expose encrypted Azure Key Vault configuration values to unauthenticated use...

Dec 18, 2025
CVE-2025-66125
5.3

This vulnerability in the Ultimate Auction WordPress plugin exposes sensitive embedded data through sent information. Attackers can retrieve confident...

Dec 16, 2025
CVE-2025-66126
5.3

This vulnerability in the WordPress Fix Media Library plugin allows attackers to retrieve embedded sensitive data from media files. It affects WordPre...

Dec 16, 2025
CVE-2025-63071
5.3

This vulnerability in the auxin-elements WordPress plugin allows attackers to retrieve embedded sensitive data through shortcodes. It affects all Word...

Dec 9, 2025
CVE-2025-62997
5.3

This vulnerability in WP EasyCart WordPress plugin allows attackers to retrieve embedded sensitive data from the plugin's responses. It affects all Wo...

Dec 9, 2025
CVE-2025-64407
5.3

Apache OpenOffice versions through 4.1.15 have an authorization vulnerability where specially crafted documents can automatically load external links ...

Nov 12, 2025
CVE-2025-62979
5.3

This vulnerability in the ACF to REST API WordPress plugin exposes sensitive data embedded in Advanced Custom Fields through the REST API. Attackers c...

Oct 27, 2025
CVE-2025-62062
5.3

This vulnerability in the WordPress Easy Post Submission plugin allows attackers to retrieve embedded sensitive data from submitted posts. It affects ...

Oct 22, 2025
CVE-2025-59268
5.3

This vulnerability allows unauthenticated remote attackers to access undisclosed endpoints containing static non-sensitive information through the BIG...

Oct 15, 2025

About CWE-201 (CWE-201)

Our database tracks 146 CVEs classified as CWE-201, with 5 rated critical and 40 rated high severity. The average CVSS score for CWE-201 vulnerabilities is 6.2.

External reference: View CWE-201 on MITRE CWE →

Monitor CWE-201 Vulnerabilities

Get alerted when new CWE-201 CVEs affect your infrastructure.

Start Monitoring Free