目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-201 通过发送数据的信息暴露 类漏洞列表 391

CWE-201 通过发送数据的信息暴露 类弱点 391 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-201属于信息泄露类漏洞,指代码在向外部实体传输数据时,意外包含了不应被该实体访问的敏感信息。攻击者通常通过拦截网络流量或日志分析,窃取如密码、密钥或个人隐私等机密数据,进而实施身份伪造或进一步渗透。开发者应避免在日志、调试输出或API响应中记录敏感字段,采用数据最小化原则,并对传输内容进行加密与脱敏处理,确保仅传输必要且授权的信息。

MITRE CWE 官方描述
CWE:CWE-201 将敏感信息插入到发送数据中 英文:代码将数据发送给另一个实体,但数据的一部分包含该实体不应访问的敏感信息。
常见影响 (1)
Confidentiality Read Files or Directories, Read Memory, Read Application Data
Sensitive data may be exposed to attackers.
缓解措施 (4)
Requirements Specify which data in the software should be regarded as sensitive. Consider which types of users should have access to which types of data.
Implementation Ensure that any possibly sensitive data specified in the requirements is verified with designers to ensure that it is either a calculated risk or mitigated elsewhere. Any information that is not necessary to the functionality should be removed in order to lower both the overhead and the possibility of security sensitive data being sent.
System Configuration Setup default error messages so that unexpected errors do not disclose sensitive information.
Architecture and Design Compartmentalize the system to have "safe" areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area. Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separatio…
代码示例 (1)
The following is an actual MySQL error statement:
Warning: mysql_pconnect(): Access denied for user: 'root@localhost' (Using password: N1nj4) in /usr/local/www/wi-data/includes/database.inc on line 4
Result · SQL
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-97302 WordPress MPG plugin <= 4.2.3 - Sensitive Data Exposure vulnerability — MPG 5.3 Medium 2026-09-30
CVE-2026-97261 WordPress Notivo plugin <= 1.4.2 - Sensitive Data Exposure vulnerability — Notivo 5.3 Medium 2026-09-30
CVE-2026-97241 WordPress BackupEase plugin <= 2.2.2 - Sensitive Data Exposure vulnerability — BackupEase 7.5 High 2026-09-30
CVE-2026-97240 WordPress StifLi Backup Tools plugin <= 2.2.7 - Sensitive Data Exposure vulnerability — StifLi Backup Tools 7.5 High 2026-09-30
CVE-2026-86450 Parla Auto DetaWix 移动端门户敏感数据泄露漏洞 — DetaWix Mobile Web Portal 7.5 High 2026-09-29
CVE-2026-101043 pnpm 11.0.0至11.11.0 环境变量泄露漏洞 — pnpm 7.4 High 2026-09-27
CVE-2026-82837 GitLab 敏感信息插入发送数据漏洞 — GitLab 5.3 Medium 2026-09-15
CVE-2026-91198 GrowthBook 5.0.1 信息泄露漏洞 — growthbook 5.3 Medium 2026-09-14
CVE-2026-78336 Apache Syncope 信息泄露漏洞 — Apache Syncope - - 2026-09-14
CVE-2026-62088 WordPress ElasticPress 信息泄露漏洞 — ElasticPress 5.3 Medium 2026-09-11
CVE-2026-81804 WordPress ZHBackup 信息泄露漏洞 — ZHBackup – Backup, Restore &amp; Migration 7.5 High 2026-09-10
CVE-2026-78374 Joomla Page Builder < 2.3.0 邮件中继漏洞 — T4 Page Builder extension for Joomla 6.9 Medium 2026-09-10
CVE-2026-78303 SP Property 4.1.4 前表单操作与邮件漏洞 — SP Property extension for Joomla 6.9 Medium 2026-09-10
CVE-2026-87015 Open WebUI 信息泄露漏洞 — open-webui 6.8 Medium 2026-09-09
CVE-2026-65812 Microsoft Teams 信息泄露漏洞 — Microsoft Teams for Android 6.8 Medium 2026-09-08
CVE-2026-86505 JetBrains IntelliJ IDEA 信息泄露漏洞 — IntelliJ IDEA 3.3 Low 2026-09-07
CVE-2026-86497 JetBrains YouTrack 信息泄露漏洞 — YouTrack 6.8 Medium 2026-09-07
CVE-2026-82209 curl 信息泄露漏洞 — curl - - 2026-09-06
CVE-2026-80255 curl 信息泄露漏洞 — curl - - 2026-09-06
CVE-2026-85307 WordPress KP Agent Ready 信息泄露漏洞 — KP Agent Ready 5.3 Medium 2026-09-03
CVE-2026-77123 Sonatype Nexus Repository Manager 信息泄露漏洞 — Nexus Repository 3 6.0 Medium 2026-09-02
CVE-2026-81162 Drupal DXPR Builder 信息泄露漏洞 — DXPR Builder: The Best Editing (AI) Experience for Drupal - - 2026-09-02
CVE-2026-81280 ukrsolution print labels with barcodes 信息泄露漏洞 — Print Barcode Labels for your WooCommerce products/orders 6.5 Medium 2026-08-31
CVE-2026-66585 WordPress WPCafe Pro 信息泄露漏洞 — WP Cafe Pro 7.5 High 2026-08-24
CVE-2026-59809 SiYuan 信息泄露漏洞 — siyuan 4.9 Medium 2026-08-22
CVE-2026-63481 Orange Hurl 信息泄露漏洞 — hurl 6.9 Medium 2026-08-20
CVE-2026-75953 J-BusinessDirectory <6.2.3 开放邮件中继漏洞 — J-BusinessDirectory extension for Joomla - - 2026-08-19
CVE-2026-73386 WordPress Track Geolocation Of Users Using Contact Form 7 信息泄露漏洞 — Track Geolocation Of Users Using Contact Form 7 7.5 High 2026-08-19
CVE-2026-73384 WordPress Pay with Contact Form 7 信息泄露漏洞 — Pay with Contact Form 7 7.5 High 2026-08-19
CVE-2026-74008 WordPress Shortcodes and extra features for Phlox theme 信息泄露漏洞 — Shortcodes and extra features for Phlox theme 5.3 Medium 2026-08-18

CWE-201(通过发送数据的信息暴露) 是常见的弱点类别,本平台收录该类弱点关联的 391 条 CVE 漏洞。