Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-201 (通过发送数据的信息暴露) — Vulnerability Class 360

360 vulnerabilities classified as CWE-201 (通过发送数据的信息暴露). AI Chinese analysis included.

CWE-201 represents an information exposure weakness where software inadvertently transmits sensitive data to unauthorized external actors. This vulnerability typically arises when developers fail to sanitize output streams, allowing credentials, personal identifiable information, or internal system states to leak through network logs, error messages, or API responses. Attackers exploit this by intercepting traffic or analyzing server-side feedback to harvest critical secrets, facilitating further unauthorized access or identity theft. To mitigate this risk, developers must implement strict data filtering and validation protocols before transmission. Utilizing secure logging frameworks that mask sensitive fields, employing encryption for data in transit, and conducting regular code reviews to identify accidental data leaks are essential practices. Ensuring that only necessary, non-sensitive information is shared with external entities significantly reduces the attack surface and protects user privacy.

MITRE CWE Description
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
Common Consequences (1)
ConfidentialityRead Files or Directories, Read Memory, Read Application Data
Sensitive data may be exposed to attackers.
Mitigations (4)
RequirementsSpecify which data in the software should be regarded as sensitive. Consider which types of users should have access to which types of data.
ImplementationEnsure that any possibly sensitive data specified in the requirements is verified with designers to ensure that it is either a calculated risk or mitigated elsewhere. Any information that is not necessary to the functionality should be removed in order to lower both the overhead and the possibility of security sensitive data being sent.
System ConfigurationSetup default error messages so that unexpected errors do not disclose sensitive information.
Architecture and DesignCompartmentalize the system to have "safe" areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area. Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separatio…
Examples (1)
The following is an actual MySQL error statement:
Warning: mysql_pconnect(): Access denied for user: 'root@localhost' (Using password: N1nj4) in /usr/local/www/wi-data/includes/database.inc on line 4
Result · SQL
CVE IDTitleCVSSSeverityPublished
CVE-2026-24477 AnythingLLM has key leak in `systemSettings.js` — anything-llm 9.1AICriticalAI2026-01-26
CVE-2026-24430 Tenda W30E V2 HTTP Responses Expose Plaintext Credentials — W30E V2 7.5AIHighAI2026-01-26
CVE-2026-24589 WordPress Cargus plugin <= 1.5.8 - Sensitive Data Exposure vulnerability — Cargus 5.3 Medium2026-01-23
CVE-2026-24565 WordPress B Accordion plugin <= 2.0.2 - Sensitive Data Exposure vulnerability — B Accordion 6.5 Medium2026-01-23
CVE-2026-24559 WordPress Integration for Contact Form 7 HubSpot plugin <= 1.4.3 - Sensitive Data Exposure vulnerability — Integration for Contact Form 7 HubSpot 5.3 Medium2026-01-23
CVE-2026-24557 WordPress Contact Form 7 GetResponse Extension plugin <= 1.0.8 - Sensitive Data Exposure vulnerability — Contact Form 7 GetResponse Extension 5.3 Medium2026-01-23
CVE-2025-68035 WordPress Tabby Checkout plugin <= 5.8.4 - Sensitive Data Exposure vulnerability — Tabby Checkout 7.5 High2026-01-22
CVE-2025-68006 WordPress Booking Ultra Pro plugin <= 1.1.23 - Sensitive Data Exposure vulnerability — Booking Ultra Pro 6.5 Medium2026-01-22
CVE-2025-63019 WordPress Cookies and Content Security Policy plugin <= 2.34 - Sensitive Data Exposure vulnerability — Cookies and Content Security Policy 5.3 Medium2026-01-22
CVE-2026-23878 HotCRP vulnerable to exposure of submitted documents — hotcrp 6.5 Medium2026-01-19
CVE-2026-22246 Local Mastodon users can enumerate and access severed relationships of every other local user — mastodon 6.5 Medium2026-01-08
CVE-2025-67931 WordPress BulletProof Security plugin <= 6.9 - Sensitive Data Exposure vulnerability — BulletProof Security 7.5 High2026-01-08
CVE-2026-22539 INFORMATION DISCLOSURE VIA CURL REQUESTS (OCPP) — QC 60/90/120 5.3 -2026-01-07
CVE-2025-59955 Coolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members` API endpoint — coolify 7.1 -2026-01-05
CVE-2025-68033 WordPress Custom Related Posts plugin <= 1.8.0 - Sensitive Data Exposure vulnerability — Custom Related Posts 7.5 High2026-01-05
CVE-2025-68029 WordPress Wallet System for WooCommerce plugin <= 2.7.3 - Sensitive Data Exposure vulnerability — Wallet System for WooCommerce 7.5 -2026-01-05
CVE-2025-68014 WordPress AweBooking plugin <= 3.2.26 - Sensitive Data Exposure vulnerability — AweBooking 6.5 Medium2026-01-05
CVE-2025-62126 WordPress Varnish/Nginx Proxy Caching plugin <= 1.8.3 - Sensitive Data Exposure vulnerability — Varnish/Nginx Proxy Caching 5.3 Medium2025-12-31
CVE-2025-59136 WordPress Gerencianet Oficial plugin <= 3.1.3 - Sensitive Data Exposure vulnerability — Gerencianet Oficial 5.3 Medium2025-12-31
CVE-2025-62139 WordPress Terms descriptions plugin <= 3.4.10 - Sensitive Data Exposure vulnerability — Terms descriptions 5.3 Medium2025-12-31
CVE-2025-59003 WordPress ColorWay Theme <= 4.2.3 - Sensitive Data Exposure Vulnerability — ColorWay 5.8 Medium2025-12-31
CVE-2025-68989 WordPress Contact Form 7 Extension For Mailchimp plugin <= 0.9.68 - Sensitive Data Exposure vulnerability — contact-form-7-mailchimp-extension 4.3 Medium2025-12-30
CVE-2025-68040 WordPress WP Project Manager plugin <= 3.0.1 - Sensitive Data Exposure vulnerability — WP Project Manager 6.5 Medium2025-12-29
CVE-2025-68516 WordPress Tablesome plugin <= 1.1.35.1 - Sensitive Data Exposure vulnerability — Tablesome 5.0 Medium2025-12-24
CVE-2025-62998 WordPress WP AI CoPilot plugin <= 1.2.7 - Sensitive Data Exposure vulnerability — WP AI CoPilot 5.0 Medium2025-12-18
CVE-2025-14823 Certificate Signing Extension Returns Encrypted Values — ScreenConnect 5.3 Medium2025-12-18
CVE-2025-66116 WordPress Ultimate Member Widgets for Elementor plugin <= 2.3 - Sensitive Data Exposure vulnerability — Ultimate Member Widgets for Elementor 7.5 High2025-12-18
CVE-2025-64295 WordPress All In One SEO Pack plugin <= 4.8.6.1 - Sensitive Data Exposure vulnerability — All In One SEO Pack 6.5 Medium2025-12-18
CVE-2025-64218 WordPress Passster plugin <= 4.2.19 - Sensitive Data Exposure vulnerability — Passster 7.5 High2025-12-18
CVE-2025-64213 WordPress MasterStudy LMS Pro plugin < 4.7.16 - Sensitive Data Exposure vulnerability — MasterStudy LMS Pro 7.5 High2025-12-18

Vulnerabilities classified as CWE-201 (通过发送数据的信息暴露) represent 360 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.