CWE-201: CWE-201

146
Total CVEs
5
Critical
40
High
6.2
Avg CVSS

Yearly Trend

2026
22
2025
105
2024
13
2023
2
2021
2

Top Affected Vendors

1 Cisco 5
2 Liferay 4
3 Gitlab 3
4 Apache 3
5 Xwiki 2
6 F5 2
7 Wpmailster 2
8 File Entity Project 1
9 Connectwise 1
10 Pomerium 1

All CWE-201 CVEs (146)

CVE-2025-11025
5.3

This vulnerability in Vimesoft Corporate Messaging Platform allows attackers to retrieve embedded sensitive data from sent messages. It affects organi...

Sep 26, 2025
CVE-2025-60140
5.3

The Tribal WordPress plugin versions up to 1.3.3 contains a vulnerability where sensitive information is embedded in sent data, potentially allowing a...

Sep 26, 2025
CVE-2025-60125
5.3

This vulnerability in the FoodBook WordPress plugin allows attackers to retrieve embedded sensitive data through insertion of information into sent da...

Sep 26, 2025
CVE-2025-58226
5.3

This vulnerability in the 3D FlipBook WordPress plugin allows attackers to retrieve embedded sensitive data from flipbooks. It affects all WordPress s...

Sep 22, 2025
CVE-2025-57922
5.3

This vulnerability in the EnvΓ­os Coordinadora Woocommerce WordPress plugin exposes sensitive information embedded in sent data. Attackers can retriev...

Sep 22, 2025
CVE-2025-57923
5.3

The UK Address Postcode Validation WordPress plugin exposes API keys in sent data, allowing unauthorized third parties to steal and misuse them. This ...

Sep 22, 2025
CVE-2025-48361
5.3

This vulnerability in Hesabfa Accounting WordPress plugin exposes sensitive data through log files. Attackers can retrieve embedded sensitive informat...

Aug 28, 2025
CVE-2025-53322
5.3

This vulnerability in the Accept Authorize.NET Payments Using Contact Form 7 WordPress plugin exposes sensitive payment data embedded in form submissi...

Jun 27, 2025
CVE-2025-5733
5.3

The Modern Events Calendar Lite WordPress plugin versions up to 7.21.9 expose full web server path information to unauthenticated attackers through im...

Jun 6, 2025
CVE-2025-48996
5.3

An unauthenticated information disclosure vulnerability in HAX open-apis allows remote attackers to retrieve a full list of PSU websites hosted on HAX...

Jun 2, 2025
CVE-2025-39498
5.3

This vulnerability in the Spotlight Social Media Feeds Premium WordPress plugin allows attackers to retrieve embedded sensitive data from the plugin's...

May 26, 2025
CVE-2025-31842
5.3

This vulnerability in the Viral Loops WP Integration WordPress plugin allows attackers to retrieve sensitive data embedded in sent information. It aff...

Apr 1, 2025
CVE-2025-30609
5.3

This vulnerability allows attackers to retrieve embedded sensitive data from the AppExperts WordPress to Mobile App plugin. It affects WordPress sites...

Mar 24, 2025
CVE-2025-22303
5.3

This vulnerability in WP Mailster WordPress plugin allows attackers to retrieve embedded sensitive data from sent emails. It affects all WP Mailster i...

Jan 7, 2025
CVE-2024-37881
5.3

The SiteGuard WP Plugin vulnerability exposes the customized login page path through wp-register.php redirection. Attackers can discover hidden login ...

Jun 19, 2024
CVE-2025-62998
5.0

This vulnerability in WP AI CoPilot WordPress plugin allows attackers to retrieve embedded sensitive data from the plugin's sent data. It affects all ...

Dec 18, 2025
CVE-2025-20348
5.0

This vulnerability allows authenticated low-privileged attackers to bypass authorization controls on REST API endpoints in Cisco Nexus Dashboard and N...

Aug 27, 2025
CVE-2025-15329
4.9

CVE-2025-15329 is an information disclosure vulnerability in Tanium Threat Response that allows unauthorized access to sensitive data. Organizations u...

Feb 5, 2026
CVE-2025-49408
4.9

This vulnerability in the Templately WordPress plugin exposes sensitive embedded data through sent information. Attackers can retrieve confidential in...

Aug 20, 2025
CVE-2026-25008
4.3

This vulnerability in the Ninja Tables WordPress plugin allows attackers to retrieve embedded sensitive data through improper handling of sent informa...

Feb 19, 2026
CVE-2025-67857
4.3

This vulnerability in Moodle exposes user identifiers in URLs during anonymous assignment submissions, compromising intended anonymity. Attackers can ...

Feb 3, 2026
CVE-2025-63007
4.3

This vulnerability in the EventPrime WordPress plugin allows attackers to retrieve embedded sensitive data through information insertion into sent dat...

Dec 9, 2025
CVE-2025-62994
4.3

This vulnerability in the WP AI CoPilot WordPress plugin allows attackers to retrieve embedded sensitive data through information leakage in sent data...

Dec 9, 2025
CVE-2025-7000
4.3

This vulnerability in GitLab allows unauthorized users to view confidential branch names when accessing project issues with related merge requests. It...

Nov 15, 2025
CVE-2025-2615
4.3

This vulnerability allows blocked GitLab users to access sensitive information by establishing GraphQL subscriptions through WebSocket connections. It...

Nov 15, 2025
CVE-2025-64351
4.3

This vulnerability in Rank Math SEO WordPress plugin exposes sensitive embedded data that could be retrieved by attackers. It affects all WordPress si...

Oct 31, 2025
CVE-2025-60095
4.3

This vulnerability in the Stackable WordPress plugin allows attackers to retrieve embedded sensitive data through information leakage in sent data. It...

Sep 26, 2025
CVE-2025-58246
4.3

This WordPress vulnerability allows users with contributor-level privileges to embed sensitive data into sent content, potentially exposing informatio...

Sep 23, 2025
CVE-2025-58649
4.3

This vulnerability in All In One SEO Pack WordPress plugin exposes sensitive embedded data through sent responses. Attackers can retrieve information ...

Sep 22, 2025
CVE-2025-58252
4.3

This vulnerability in the Getwid WordPress plugin allows attackers to retrieve embedded sensitive data through information leakage in sent responses. ...

Sep 22, 2025
CVE-2025-58249
4.3

This vulnerability in the Qubely WordPress plugin allows attackers to retrieve embedded sensitive data that should not be exposed. It affects all Word...

Sep 22, 2025
CVE-2025-44017
4.3

The Gunosy mobile app contains an information disclosure vulnerability where JSON Web Tokens (JWTs) may be leaked in outbound communications. If users...

Sep 2, 2025
CVE-2025-55710
4.3

This vulnerability in TaxoPress WordPress plugin exposes sensitive embedded data through sent information. Attackers can retrieve confidential informa...

Aug 14, 2025
CVE-2025-48381
4.3

This vulnerability allows authenticated CVAT users to enumerate all task, project, label, job, and quality report IDs and names on the instance. It ca...

May 30, 2025
CVE-2025-2565
4.3

This vulnerability allows unauthorized users to access form entry data in affected Liferay versions. It affects Liferay Portal 7.4.0-7.4.3.126 and mul...

Mar 20, 2025
CVE-2024-45653
4.3

IBM Sterling Connect:Direct Web Services versions 6.0-6.3 expose sensitive IP address information to authenticated users in API responses. This inform...

Jan 19, 2025
CVE-2021-1425
4.3

This vulnerability in Cisco Content Security Management Appliance (SMA) allows authenticated remote attackers to access sensitive information, includi...

Nov 18, 2024
CVE-2024-43814
4.3

The goTenna Pro ATAK Plugin's default settings broadcast user location data every 60 seconds without encryption when the plugin is active. This vulner...

Sep 26, 2024
CVE-2025-52639
3.5

HCL Connections has an information disclosure vulnerability where improper rendering of application data allows authenticated users to access sensitiv...

Nov 18, 2025
CVE-2025-49300
2.7

This vulnerability in the Traveler Option Tree WordPress plugin exposes sensitive embedded data through sent responses. Attackers can retrieve informa...

Dec 16, 2025
CVE-2025-64299
2.7

LogStare Collector contains an information disclosure vulnerability where administrative users can access other users' password hashes. This affects a...

Nov 21, 2025
CVE-2026-24427
N/A

Tenda AC7 routers expose administrative credentials in plaintext within web management responses, allowing attackers to steal router passwords. The vu...

Feb 3, 2026
CVE-2026-22539
N/A

This vulnerability allows unauthenticated attackers with knowledge of the OCPP v1.6 protocol to obtain information from electric vehicle chargers. It ...

Jan 7, 2026
CVE-2025-66566
N/A

This vulnerability in yawkat LZ4 Java library allows attackers to read previous contents of output buffers when processing crafted compressed input. A...

Dec 5, 2025
CVE-2025-65944
N/A

Sentry-Javascript SDK versions 10.11.0 to 10.27.0 inadvertently send sensitive HTTP headers like Cookie to Sentry when sendDefaultPii is enabled. This...

Nov 25, 2025
CVE-2025-64502
N/A

Parse Server versions before 8.5.0-alpha.5 allow unauthenticated clients to execute MongoDB explain() queries without requiring the master key. This e...

Nov 10, 2025

About CWE-201 (CWE-201)

Our database tracks 146 CVEs classified as CWE-201, with 5 rated critical and 40 rated high severity. The average CVSS score for CWE-201 vulnerabilities is 6.2.

External reference: View CWE-201 on MITRE CWE →

Monitor CWE-201 Vulnerabilities

Get alerted when new CWE-201 CVEs affect your infrastructure.

Start Monitoring Free