Skip to main content

Threats Tagged 'cwe-201'

View all threats tagged with 'cwe-201'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-201

Threats Tagged 'cwe-201'

Click on any threat for detailed analysis and mitigation recommendations

BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Timestamp node's tsaUrl control from imported JSON without schema or destination validation. When a user imports the crafted workflow and runs it against a PDF, timestampPdf() sends an RFC 3161 TimeStampReq containing the PDF's SHA-256 MessageImprint to the attacker-selected endpoint. The default self-hosted configuration does not set VITE_CORS_PROXY_URL, so the request bypasses the proxy's ALLOWED_TSA_HOSTS checks and is sent directly. The disclosed digest can confirm that a document matches a known file and can correlate the same document across users without revealing its contents. This vulnerability is fixed in 2.8.7.

Join the discussion

CVE-2026-54649 is a low-severity vulnerability in punchin-email, a Cloudflare Email Worker by PunchIn-App. Versions prior to 1.5.0 improperly handle inbound alias mail, causing the Reply-To header to be dropped. This leads to the operator's private inbox address being exposed to correspondents when replying to alias emails. The exposure is limited to the operator's own email address and does not affect third-party data or allow code execution or authentication bypass. The issue is fixed in version 1.5.0.

Join the discussion

Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client secrets, regardless of the entitlements owned by the caller. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

Join the discussion

Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation. Crafted repository content can cause the agent to modify the workspace settings file, which redirects the Kiro Powers registry request to an actor controlled endpoint and sends workspace data to that endpoint when the Powers panel is opened. To remediate this issue, users should upgrade to Kiro IDE version 0.8.135 or later. Users who opened a project in an earlier version should also rotate any credentials that were present in that project.

Join the discussion

Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation. Crafted repository content can cause the agent to modify the workspace settings file, which redirects the Kiro Powers registry request to an actor controlled endpoint and sends workspace data to that endpoint when the Powers panel is opened. To remediate this issue, users should upgrade to Kiro IDE version 0.8.135 or later. Users who opened a project in an earlier version should also rotate any credentials that were present in that project.

Join the discussion

Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. This issue affects ElasticPress: from n/a through 5.3.4.

Join the discussion

Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration <= 2.4.2 versions.

Join the discussion

CVE-2026-78374 is a medium severity vulnerability in the T4 Page Builder extension for Joomla by joomlart.com. Versions 1.0.0 through 2.2.0 are affected. The vulnerability allows unauthenticated attackers to send emails via an open mail relay through the front-end JSON editor's contact AJAX endpoint. This endpoint lacks authentication, CSRF protection, captcha enforcement (if no captcha plugin is enabled), and rate limiting. Attackers can fully control the recipient, subject, and HTML body of the email, which is sent from the site's configured sender identity.

Join the discussion

A vulnerability in the SP Property extension for Joomla versions 1.0.0 through 4.1.3 allows unvalidated email destination and form manipulation in booking requests. This occurs because booking inquiries rely on client-submitted hidden fields for recipient routing, which can be manipulated to insert sensitive information into sent data. The issue is tracked as CVE-2026-78303 with a medium severity rating and a CVSS score of 6.9.

Join the discussion

Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

Join the discussion

Showing 1 to 10 of 155 results

Filters:Tag: cwe-201
Page 1 of 16
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses