Skip to main content

Threats Tagged 'cwe-202'

View all threats tagged with 'cwe-202'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-202

Threats Tagged 'cwe-202'

Click on any threat for detailed analysis and mitigation recommendations

Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation. This issue affects MediaWiki PageTriage extension: 1.46, 1.45, and 1.43.

Join the discussion

Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access LinkedAccount's (if present) or Manager's (if defined) sensitive information, possibly including hashed credentials. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

Join the discussion

CVE-2026-16520 is a high-severity vulnerability affecting multiple versions of Genians Genian NAC and Genian ZTNA products. It involves improper input validation and exposure of sensitive information through data queries, leading to SQL Injection and authentication bypass. The affected versions span Genian NAC V4.0, V5.0, and Genian ZTNA V6.0, with specific version ranges detailed. The vulnerability has a CVSS 4.0 base score of 8.7, indicating a significant risk if exploited.

Join the discussion

CVE-2026-25703 is a high-severity vulnerability in SUSE NeuVector versions up to and including 5.4.9. It involves missing authentication for the critical /network/graph API in the manager component, which can lead to potential information leakage through cached sensitive data.

Join the discussion

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or workspace. The response can exceed 100MB and includes sensitive configuration data, including Vector Store settings such as Qdrant Server URL and collection name. The observed behavior indicates missing or insufficient authorization checks, workspace/project/tenant isolation, and pagination or limits, exposing integration parameters and infrastructure details that may enable further targeted attacks. This issue is fixed in version 3.1.3.

Join the discussion

Apache Syncope contains a vulnerability that allows exposure of sensitive information through crafted data queries. Specifically, an administrator with entitlements to manage Derived Schemas can create malicious JEXL expressions. These expressions enable any administrator with User read entitlements to access security-sensitive user information. The issue affects Apache Syncope versions 3.0 through 3.0.16, 4.0 through 4.0.5, and 4.1.0. Upgrading to versions 4.0.6 or 4.1.1 mitigates this vulnerability by restricting JEXL expression definitions.

Join the discussion

CVE-2026-30778 is a vulnerability in Apache SkyWalking versions 9.7.0 through 10.3.0 where the /debugging/config/dump endpoint may expose sensitive configuration information related to MySQL and PostgreSQL databases. This exposure can lead to unauthorized access to critical configuration data. The issue is resolved in Apache SkyWalking version 10.4.0, which users are advised to upgrade to. The vulnerability has a CVSS score of 7.

Join the discussion

The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.2. The eshot_form_builder_get_account_data() function is registered as a wp_ajax_ AJAX handler accessible to all authenticated users. The function lacks any capability check (e.g., current_user_can('manage_options')) and does not verify a nonce. It directly queries the database for the e-shot API token stored in the eshotformbuilder_control table and returns it along with all subaccount data as a JSON response. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract the e-shot API token and subaccount information, which could then be used to access the victim's e-shot platform account.

Join the discussion

Vendure is an open-source headless commerce platform. Prior to version 3.5.3, the `NativeAuthenticationStrategy.authenticate()` method is vulnerable to a timing attack that allows attackers to enumerate valid usernames (email addresses). In `packages/core/src/config/auth/native-authentication-strategy.ts`, the authenticate method returns immediately if a user is not found. The significant timing difference (~200-400ms for bcrypt vs ~1-5ms for DB miss) allows attackers to reliably distinguish between existing and non-existing accounts. Version 3.5.3 fixes the issue.

Join the discussion

CVE-2025-68456 is a high-severity vulnerability in Craft CMS versions 3.0.0 through 4.16.16 and 5.0.0-RC1 through 5.8.20 that allows unauthenticated users to trigger database backup operations. This can lead to resource exhaustion or potential information disclosure due to lack of limits or throttling on resource allocation.

Join the discussion

Showing 1 to 10 of 15 results

Filters:Tag: cwe-202
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses