Exposure of Sensitive Information

CWE-200 · 13 records · 6 with a public proof-of-concept

Records the NVD classes as Exposure of Sensitive Information (CWE-200), highest CVSS first.

  1. HIGH 7.5CVE-2026-61891public PoC

    In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without

    theia

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-16604

    The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected content without knowing the password.

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-16603

    The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated users to read the full content, title, and excerpt of category-locked posts through the core REST API.

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.5CVE-2026-16602

    The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint, allowing unauthenticated users to disclose the content of non-public (draft, private, and pending) posts on si

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 6.5CVE-2026-16968

    The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 6.5CVE-2026-70491public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in backend/open_webui/routers/tools.py returned full Python too

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 6.5CVE-2026-18809

    Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153.0.3.

    AI risk analysis on Exploit-DB.ai →

  8. MEDIUM 6.2CVE-2026-71293public PoC

    Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case for the handle that returns the user's raw two-factor recovery codes with no access restriction.

    AI risk analysis on Exploit-DB.ai →

  9. MEDIUM 4.8CVE-2026-70590public PoC

    Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead to account takeover if

    AI risk analysis on Exploit-DB.ai →

  10. MEDIUM 4.3CVE-2026-17515

    The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport:

    AI risk analysis on Exploit-DB.ai →

  11. LOW 3.7CVE-2026-16993

    The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file, so on a web server that does not honor .htaccess (suc

    AI risk analysis on Exploit-DB.ai →

  12. UNSCOREDCVE-2026-70478public PoC

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The endpoint decrypts the s

    AI risk analysis on Exploit-DB.ai →

  13. UNSCOREDCVE-2026-70473public PoC

    Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or work

    AI risk analysis on Exploit-DB.ai →