CWE-201Base

Insertion of Sensitive Information Into Sent Data

Draft in the CWE catalog · 388 CVEs mapped

388
CVEs mapped
6.5
Median CVSS
What it is

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Recent examples
5.3cvss
CVE-2026-85307

CVE-2026-85307 - MEDIUM Severity Vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data. This issue affects KP Agent Ready: from n/a before 1.2.08.

MEDIUMno explanation yet
0%
epss
none
CVE-2026-77123

CVE-2026-77123 - UNKNOWN Severity Vulnerability

Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the nexus:capabilities:read privilege can retrieve the plaintext shared secret configured on a webhook capability, which is intended to be masked from all API responses. This issue affects Nexus Repository 3 versions 3.2.0 through 3.95.x, and is fixed in version 3.96.0.

no explanation yet
0%
epss
5.3cvss
CVE-2026-81162

CVE-2026-81162 - MEDIUM Severity Vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-201
Abstraction
Base
Structure
Simple
Status
Draft
References (1)