Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-201 (通过发送数据的信息暴露) — Vulnerability Class 338

338 vulnerabilities classified as CWE-201 (通过发送数据的信息暴露). AI Chinese analysis included.

CWE-201 represents an information exposure weakness where software inadvertently transmits sensitive data to unauthorized external actors. This vulnerability typically arises when developers fail to sanitize output streams, allowing credentials, personal identifiable information, or internal system states to leak through network logs, error messages, or API responses. Attackers exploit this by intercepting traffic or analyzing server-side feedback to harvest critical secrets, facilitating further unauthorized access or identity theft. To mitigate this risk, developers must implement strict data filtering and validation protocols before transmission. Utilizing secure logging frameworks that mask sensitive fields, employing encryption for data in transit, and conducting regular code reviews to identify accidental data leaks are essential practices. Ensuring that only necessary, non-sensitive information is shared with external entities significantly reduces the attack surface and protects user privacy.

MITRE CWE Description
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
Common Consequences (1)
ConfidentialityRead Files or Directories, Read Memory, Read Application Data
Sensitive data may be exposed to attackers.
Mitigations (4)
RequirementsSpecify which data in the software should be regarded as sensitive. Consider which types of users should have access to which types of data.
ImplementationEnsure that any possibly sensitive data specified in the requirements is verified with designers to ensure that it is either a calculated risk or mitigated elsewhere. Any information that is not necessary to the functionality should be removed in order to lower both the overhead and the possibility of security sensitive data being sent.
System ConfigurationSetup default error messages so that unexpected errors do not disclose sensitive information.
Architecture and DesignCompartmentalize the system to have "safe" areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area. Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separatio…
Examples (1)
The following is an actual MySQL error statement:
Warning: mysql_pconnect(): Access denied for user: 'root@localhost' (Using password: N1nj4) in /usr/local/www/wi-data/includes/database.inc on line 4
Result · SQL
CVE IDTitleCVSSSeverityPublished
CVE-2025-48261 WordPress MultiVendorX plugin <= 4.2.22 - Sensitive Data Exposure Vulnerability — MultiVendorX 7.5 High2025-06-09
CVE-2025-49294 WordPress Crawlomatic Multisite Scraper Post Generator plugin <= 2.6.8.2 - Sensitive Data Exposure via Log Exposure vulnerability — Crawlomatic Multisite Scraper Post Generator 5.3 Medium2025-06-06
CVE-2025-5733 Modern Events Calendar <= 7.21.9 - Information Exposure — Modern Events Calendar Lite 5.3 Medium2025-06-06
CVE-2025-31134 FreshRSS vulnerable to directory enumeration via ext.php — FreshRSS 5.3AIMediumAI2025-06-04
CVE-2025-48934 Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variables — deno 7.5AIHighAI2025-06-04
CVE-2025-48996 Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API Endpoint — issues 5.3 Medium2025-06-02
CVE-2025-48331 WordPress WooCommerce Orders & Customers Exporter <= 5.0 - Sensitive Data Exposure Vulnerability — WooCommerce Orders & Customers Exporter 7.5 High2025-05-30
CVE-2025-48381 CVAT has information disclosure via browsable API — cvat 4.3AIMediumAI2025-05-30
CVE-2025-48045 MICI Network Co. Ltd. NetFax Server Default Administrator Credentials Disclosure — NetFax Server 7.5AIHighAI2025-05-29
CVE-2025-39498 WordPress Spotlight - Social Media Feeds (Premium) plugin <= 1.7.1 - Sensitive Data Exposure vulnerability — Spotlight - Social Media Feeds (Premium) 5.3 Medium2025-05-26
CVE-2025-47541 WordPress Mail Mint plugin <= 1.17.7 - Sensitive Data Exposure Vulnerability — Mail Mint 7.5 High2025-05-23
CVE-2025-48219 O2 VoLTE 安全漏洞 — O2 3.5 Low2025-05-18
CVE-2025-47775 Bullfrog's DNS over TCP bypasses domain filtering — bullfrog 6.2 Medium2025-05-14
CVE-2025-3529 WordPress Simple PayPal Shopping Cart <= 5.1.2 - Unauthenticated Information Exposure via file_url Parameter — Simple Shopping Cart 8.2 High2025-04-23
CVE-2025-32594 WordPress Simple WP Events plugin <= 1.8.17 - Sensitive Data Exposure vulnerability — Simple WP Events 7.5 High2025-04-17
CVE-2025-32635 WordPress Hive Support plugin <= 1.2.6 - Sensitive Data Exposure vulnerability — Hive Support 7.5 High2025-04-17
CVE-2025-26335 Dell PowerProtect Cyber Recovery 安全漏洞 — PowerProtect Cyber Recovery 5.8 Medium2025-04-11
CVE-2025-27244 Hammock AssetView 安全漏洞 — AssetView 7.5 -2025-04-02
CVE-2025-31842 WordPress Viral Loops WP Integration Plugin <= 3.4.0 - Sensitive Data Exposure vulnerability — Viral Loops WP Integration 5.3 Medium2025-04-01
CVE-2025-27001 WordPress Shipmondo – A complete shipping solution for WooCommerce plugin <= 5.0.3 - Authenticated Arbitrary WordPress Option Disclosure vulnerability — Shipmondo – A complete shipping solution for WooCommerce 6.5 Medium2025-03-28
CVE-2025-30609 WordPress AppExperts plugin <= 1.4.3 - Sensitive Data Exposure Vulnerability — AppExperts 5.3 Medium2025-03-24
CVE-2025-2565 Liferay Portal和Liferay DXP 安全漏洞 — Portal 7.5 -2025-03-20
CVE-2024-7872 Sensetive Data Exposure in ExtremePACS' Extreme XDS — Extreme XDS 7.6 High2025-03-06
CVE-2025-26318 TSplus Remote Access 安全漏洞 — TSplus Remote Access 5.8 Medium2025-03-04
CVE-2025-24567 WordPress WP Mailster plugin <= 1.8.16.0 - Sensitive Data Exposure vulnerability — WP Mailster 6.5 Medium2025-02-14
CVE-2025-24639 WordPress Korea for WooCommerce plugin <= 1.1.11 - Sensitive Data Exposure vulnerability — Korea for WooCommerce 6.5 Medium2025-02-03
CVE-2025-24597 WordPress Barcode Generator for WooCommerce plugin <= 2.0.2 - Sensitive Data Exposure vulnerability — Barcode Generator for WooCommerce 6.5 Medium2025-01-31
CVE-2025-24858 Gradle 安全漏洞 — Enterprise 9.8 -2025-01-26
CVE-2023-38013 IBM Cloud Pak System information disclosure — Cloud Pak System 5.3 Medium2025-01-25
CVE-2025-24582 WordPress 12 Step Meeting List plugin <= 3.16.5 - Sensitive Data Exposure vulnerability — 12 Step Meeting List 5.3 Medium2025-01-24

Vulnerabilities classified as CWE-201 (通过发送数据的信息暴露) represent 338 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.