Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache An
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is pub
The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves tem
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 d
The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does n
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti
The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker dat
The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthent
The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of
The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns
The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before
The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowin
The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connecto
The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the a
The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded thr
Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets v
Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta
An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kest
The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file downlo
The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-resto
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its
Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_EN
GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handl
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
Private Repository Metadata Remains Accessible After Access Revocation
The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check
The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some o
Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 11
CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fa
An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via t
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Manageme
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus service metrics from the
An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remote attacker to obtain sensitive information via th
Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's U
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plu
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plug
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication pl
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensit
WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens witho
urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prio
Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public shar
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started