Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-201'

View all threats tagged with 'cwe-201'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-201

Threats Tagged 'cwe-201'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-66696: CWE-201 Insertion of Sensitive Information Into Sent Data in Nexcess Gutenberg Blocks by Kadence BlocksCVE-2026-66696
0

Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.

Join the discussion
CVE-2026-66685: CWE-201 Insertion of Sensitive Information Into Sent Data in Alex Featured Video PlusCVE-2026-66685
0

Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.

Join the discussion
CVE-2026-66684: CWE-201 Insertion of Sensitive Information Into Sent Data in Akshay Menariya Export Import MenusCVE-2026-66684
0

Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.

Join the discussion
CVE-2026-66683: CWE-201 Insertion of Sensitive Information Into Sent Data in WP Zone Custom CSS and JavaScriptCVE-2026-66683
0

Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.

Join the discussion
CVE-2026-65543: CWE-201 Insertion of Sensitive Information Into Sent Data in vimeodev VimeoCVE-2026-65543
0

Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.

Join the discussion
CVE-2026-66901: CWE-918 Server-Side Request Forgery (SSRF) in CJCOLLIER Google::AuthCVE-2026-66901
0

Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the library requests are read from the credentials JSON, and their hosts were not checked against the universe domain before the request. For an external_account configuration, retrieve_subject_token fetched credential_source.url with headers from the same JSON, and fetch_access_token posted the subject token to token_url, then sent the STS access token it received to service_account_impersonation_url in an Authorization: Bearer header. The authorized_user, impersonated_service_account and service_account configurations posted the client secret and refresh token, the source access token, and a signed JWT assertion to their own JSON-supplied token_uri or impersonation URL. Any caller that builds credentials from a configuration it does not fully control issues those requests from the application's network position, reaching hosts the configuration names, including internal services and link-local metadata endpoints, and hands them the credentials each request carries. The service_account assertion is bound to aud, so it is not replayable against Google. Version 0.06 added a _validate_url host check to the external_account class, keyed on a universe_domain read from the same credentials JSON. Version 0.07 gated a JSON-supplied universe domain behind GOOGLE_EXTERNAL_ACCOUNT_ALLOW_CUSTOM_UNIVERSES=1, deriving the pin flag from arguments that an earlier BUILDARGS pass had already merged on the make_creds path. Version 0.08 passed the pin decision through as an explicit constructor argument and moved _validate_url to Google::Auth::Credentials, adding the call to UserRefreshCredentials and ImpersonatedServiceAccountCredentials, and 0.09 added it to ServiceAccountCredentials.

Join the discussion
VU#305509: OPeNDAP Hyrax is vulnerable to SSRF and Credential DisclosureCVE-2026-16637
0

OPeNDAP Hyrax contains a Server Side Request Forgery (SSRF) vulnerability that allows an attacker to bypass the allowed hosts restriction via unvalidated HTTP redirects. This flaw can cause the application to communicate with unauthorized internal or external systems. Additionally, user authentication headers, including a legacy Echo-Token credential, may be leaked to attacker-controlled endpoints during these redirects. Exploitation could enable unauthenticated attackers to access internal services and, if a user is authenticated, disclose credentials that grant access to protected datasets. No official patch is confirmed yet, but a fix is expected in Hyrax version 1.18.0 or later. Administrators are advised to restrict gateway exposure to trusted networks until a patch is available.

Join the discussion
CVE-2026-20484: CWE-201 Insertion of Sensitive Information Into Sent Data in MediaTek, Inc. MediaTek chipsetCVE-2026-20484
0

In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004.

Join the discussion
Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data. (CVE-2026-28144)CVE-2026-28144
0

Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data. This issue affects WP Maps: from n/a through 4.9.6.

Join the discussion
CVE-2026-28144: CWE-201 Insertion of Sensitive Information Into Sent Data in Flipper Code WP MapsCVE-2026-28144
0

CVE-2026-28144 is a vulnerability in the WP Maps plugin by Flipper Code that allows insertion of sensitive information into sent data, potentially exposing embedded sensitive data. It affects all versions up to and including 4.9.6. The vulnerability has a medium severity with a CVSS score of 4.3. No official patch or remediation guidance is currently available from the vendor.

Join the discussion

Showing 1 to 10 of 20 results

Filters:Tag: cwe-201
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses