Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.
Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from th
Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.
urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prio
Subscriber Sensitive Data Exposure in Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Custome
Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation & Chat Widget <= 4.2
Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.
Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. Thi
swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol
A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated,
Insertion of Sensitive Information Into Sent Data vulnerability in ZAYTECH Smart Online Order for Clover clover-online-o
Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd. Co. K12net a
Insertion of Sensitive Information Into Sent Data vulnerability in awethemes AweBooking awebooking allows Retrieve Embed
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon 4.3 added notifications of severed
HotCRP is conference review software. Starting in commit aa20ef288828b04550950cf67c831af8a525f508 and prior to commit ce
Insertion of Sensitive Information Into Sent Data vulnerability in Deetronix Booking Ultra Pro booking-ultra-pro allows
Insertion of Sensitive Information Into Sent Data vulnerability in bPlugins B Accordion b-accordion allows Retrieve Embe
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a sensitive information exposure vulnerability in
Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s configuration A
Insertion of Sensitive Information Into Sent Data vulnerability in WPVibes Elementor Addon Elements addon-elements-for-e
Insertion of Sensitive Information Into Sent Data vulnerability in RadiusTheme Classified Listing classified-listing all
OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vuln
Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allo
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being u
Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privi
OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is co
Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users
IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API resp
Subscriber Sensitive Data Exposure in XCloner <= 4.8.6 versions.
Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.
Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded
In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP r
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repositor
Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.
Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 a
IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.
Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.
Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentica
HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API respons
Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip add
Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.
Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches t
Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.
OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlis
Frequently Asked Questions
What is CWE-201?
CWE-201 (CWE-201) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-201?
There are 396 CVE records associated with CWE-201 in our database. Of these, 12 are critical severity, 103 are high severity, and 244 are medium severity.
How can I protect against CWE-201 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-201 using AI-powered security agents.
Detect CWE-201 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-201 vulnerabilities across your infrastructure.
Get Started