On this page

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Weakness Summary

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

  • Canonical source: MITRE CWE-200 (opens in a new tab)
  • Published Atomicorp CVE observations: 81
  • Distinct affected products in those observations: 73
  • Active Atomicorp rules associated with this weakness: 79

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2026-51027FileThingie v.2.5.7 Information Disclosure Vulnerability-Attack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2017-11165DataTaker DT80 dEX 1.50.012 - Information Disclosuredt80 dex firmwareAttack Blocked by Atomicorp390716
CVE-2018-0127Cisco RV132W/RV134W Router - Information Disclosurerv132w firmwareAttack Blocked by Atomicorp312863 , 390716
CVE-2018-15534Geutebrueck re_porter 7.8.974.20 - Credential Disclosurere porter 16 firmwareAttack Blocked by Atomicorp390727 , 392301 , 392648
CVE-2018-7251Anchor CMS 0.12.3 - Error Log ExposureanchorAttack Blocked by Atomicorp390716
CVE-2026-65760Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0Easy Store extension for JoomlaAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2020-9043WordPress wpCentral <1.5.1 - Information DisclosurewpcentralDetected by Atomicorp377360
CVE-2021-32819Nodejs Squirrelly - Remote Code ExecutionsquirrellyAttack Blocked by Atomicorp340014 , 340087 , 340095 , 340193 , 344370 , 345240 , 380026
CVE-2026-47394PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validatePraisonAIAttack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2026-47743Shopper: Multiple data integrity and disclosure issues in admin Livewire componentsshopperAttack Blocked by Atomicorp333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-62865TypeBot: Arbitrary server file read via Send Email block attachment pathtypebot.ioAttack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2018-16288LG SuperSign EZ CMS 2.5 - Local File Inclusionsupersign cmsAttack Blocked by Atomicorp347009
CVE-2021-32820Express-handlebars - Local File Inclusionexpress handlebarsAttack Blocked by Atomicorp344360 , 347009 , 390709
CVE-2024-21136Oracle Retail Xstore Suite - Pre-authenticated Path Traversalretail xstore officeAttack Blocked by Atomicorp340007 , 344365 , 347019
CVE-2024-24919Check Point Quantum Gateway - Information Disclosurequantum security gatewayAttack Blocked by Atomicorp392301
CVE-2026-44881Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-UpdateportainerAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2025-69755Neterbit NW-431F Router vNW-431F-20241014-IR03 Arbitrary Code Execution Vulnerability-Attack Blocked by Atomicorp340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-39363Vite Affected by Arbitrary File Read via Vite Dev Server WebSocketviteAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2016-1337Cisco EPC 3928 - Multiple Vulnerabilitiesepc3928 firmwareAttack Blocked by Atomicorp333141 , 340147 , 340148 , 340149 , 341256 , 342259 , 344363 , 346755 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2016-9314Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 - Multiple Vulnerabilitiesinterscan web security virtual applianceAttack Blocked by Atomicorp340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 , 390585
CVE-2016-3473Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injectionbusiness intelligence publisherAttack Blocked by Atomicorp330791 , 340152 , 344370 , 344372 , 380018 , 390704 , 392301
CVE-2026-53553Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server CompromisegoployAttack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2014-8675SO Planning 1.32 - Multiple VulnerabilitiessoplanningAttack Blocked by Atomicorp331028 , 340016 , 340017 , 340144 , 340155 , 340156 , 340157 , 340159 , 341155 , 341245 , 344363 , 344370 , 360147 , 360148 , 360153 , 390726 , 392647
CVE-2014-9147Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cmsAttack Blocked by Atomicorp340007 , 340156 , 341145 , 344360 , 380026 , 380122 , 390709 , 390720 , 390726 , 392647
CVE-2015-1000012WordPress MyPixs <=0.3 - Local File InclusionmypixsAttack Blocked by Atomicorp344360 , 347009 , 390709
CVE-2015-2080Inductive Automation Ignition 7.8.1 - Remote Leakage Of Shared BuffersfedoraAttack Blocked by Atomicorp344361 , 344363 , 344364 , 344365 , 390724
CVE-2016-4806Web2py 2.14.5 - Multiple Vulnerabilitiesweb2pyAttack Blocked by Atomicorp344360 , 344364 , 344366 , 344370
CVE-2016-5677NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilitiesreadynas surveillanceAttack Blocked by Atomicorp392301
CVE-2017-1000029Oracle GlassFish Server Open Source Edition 3.0.1 - Local File Inclusionglassfish serverAttack Blocked by Atomicorp347009
CVE-2017-16894Laravel <5.5.21 - Information DisclosurelaravelAttack Blocked by Atomicorp390709
CVE-2017-9812Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilitiesanti-virus for linux serverAttack Blocked by Atomicorp390704 , 390724
CVE-2018-1306Apache Portals Pluto 3.0.0 - Remote Code ExecutionplutoAttack Blocked by Atomicorp390727 , 392648
CVE-2018-3760Ruby On Rails - Local File InclusioncloudformsAttack Blocked by Atomicorp347009
CVE-2018-6008Joomla! Jtag Members Directory 5.3.7 - Local File Inclusionjtag members directoryAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2018-8033Apache OFBiz - XML External Entity InjectionofbizAttack Blocked by Atomicorp341256 , 344370 , 344372
CVE-2021-24170User Profile Picture < 2.5.0 - Sensitive Information Disclosureuser profile pictureDetected by Atomicorp377360
CVE-2021-24227Patreon WordPress <1.7.0 - Unauthenticated Local File Inclusionpatreon wordpressAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2021-41277Metabase - Local File InclusionmetabaseAttack Blocked by Atomicorp340165 , 344360 , 347009
CVE-2021-43287Pre-Auth Takeover of Build Pipelines in GoCDgocdAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2023-34092Vite Dev Server - Information ExposureviteAttack Blocked by Atomicorp390709
CVE-2023-40211Post Grid <= 2.2.50 - Information Exposure via REST APIpost grid comboAttack Blocked by Atomicorp330791 , 340152
CVE-2023-40600EWWW Image Optimizer <= 7.2.0 - Unauthenticated Information Disclosureimage optimizerAttack Blocked by Atomicorp390716
CVE-2023-44982WordPress Perfect Images (WP Retina 2x) < 6.4.6 - Sensitive Information Exposureperfect imagesAttack Blocked by Atomicorp390716
CVE-2024-12008W3 Total Cache < 2.8.2 - Log File Exposurew3 total cacheAttack Blocked by Atomicorp390716
CVE-2024-45388Hoverfly < 1.10.3 - Arbitrary File ReadhoverflyAttack Blocked by Atomicorp344360 , 390709
CVE-2024-46938Sitecore Experience Platform <= 10.4 - Arbitrary File Readexperience commerceAttack Blocked by Atomicorp340007 , 344360 , 344365 , 347019 , 390709
CVE-2025-30208Vite - Arbitrary File ReadviteAttack Blocked by Atomicorp347009 , 390709
CVE-2025-31125Vite Development Server - Path TraversalviteAttack Blocked by Atomicorp347009 , 390709 , 390716
CVE-2026-51078Dede CMS v.5.7.118 Information Disclosure Vulnerability-Attack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-61891theia Exposure of Sensitive Information to an Unauthorized Actor VulnerabilitytheiaAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2026-47735Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checksarcAttack Blocked by Atomicorp340007 , 344360 , 390709 , 390719
CVE-2024-7339TVT DVR Sensitive Device - Information Disclosuresh-4050a5-5l(mm) firmwareAttack Blocked by Atomicorp392301
CVE-2014-2383Dompdf < v0.6.0 - Local File InclusiondompdfAttack Blocked by Atomicorp340077 , 340165 , 344360 , 347009
CVE-2015-4682Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilitiesrealpresence resource managerAttack Blocked by Atomicorp330791 , 340152 , 392301
CVE-2016-6435Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusionsecure firewall management centerAttack Blocked by Atomicorp340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2018-18762SaltOS Erp Crm 3.1 r8126 - Database File DownloadsaltosAttack Blocked by Atomicorp390716
CVE-2021-22145Elasticsearch 7.10.0-7.13.3 - Information DisclosureelasticsearchAttack Blocked by Atomicorp330791 , 340152
CVE-2022-34125GLPI Activity v3.1.0 - Authenticated Local File Inclusion on Activity plugincmdbAttack Blocked by Atomicorp340007 , 344360
CVE-2026-58442Repository migration SSRF via multi-answer DNS allow-list bypassGitea Open Source Git ServerAttack Blocked by Atomicorp337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-29066TinaCMS - Path TraversaltinacmsAttack Blocked by Atomicorp347009 , 390709
CVE-2017-14955Check_MK 1.2.8p25 - Information DisclosurecheckmkAttack Blocked by Atomicorp330791 , 340152
CVE-2024-13609WordPress 1 Click Migration Plugin < 2.3 - Information Exposure1 click migrationAttack Blocked by Atomicorp350590 , 390716
CVE-2025-14528D-Link DIR-803 - Authentication Bypassdir-803 firmwareAttack Blocked by Atomicorp390722
CVE-2018-8024Apache Spark UI - Cross-Site ScriptingsparkAttack Blocked by Atomicorp340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2013-2683Cisco Linksys E4200 - Multiple Vulnerabilitieslinksys e4200 firmwareAttack Blocked by Atomicorp392301
CVE-2015-2826WordPress Plugin Simple Ads Manager - Information Disclosuresimple ads managerAttack Blocked by Atomicorp344370 , 390904
CVE-2016-1910SAP NetWeaver J2EE Engine 7.40 - SQL InjectionnetweaverAttack Blocked by Atomicorp340016 , 340156 , 341245 , 380026 , 390704
CVE-2016-2388SAP NetWeaver J2EE Engine 7.40 - SQL Injectionnetweaver application server javaAttack Blocked by Atomicorp340016 , 340156 , 341245 , 380026 , 390704
CVE-2017-9978QuantaStor Software Defined Storage < 4.3.1 - Multiple VulnerabilitiesquantastorAttack Blocked by Atomicorp330791 , 340152 , 392301
CVE-2021-34429Eclipse Jetty 11.0.5 - Sensitive File DisclosurejettyAttack Blocked by Atomicorp390703
CVE-2024-8852All-in-One WP Migration < 7.87 - Unauthenticated Information Disclosureall-in-one wp migrationAttack Blocked by Atomicorp390716
CVE-2025-11368LearnPress < 4.3.0 - Arbitrary Callback Execution to Information ExposurelearnpressAttack Blocked by Atomicorp344365
CVE-2025-31486Vite server.fs.deny Bypass - Local File InclusionviteAttack Blocked by Atomicorp347009 , 390709
CVE-2026-53452Ground Station: Unauthenticated out-of-containment file read via sigmfplayback recordingPathground-stationAttack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2026-73082Activepieces: Server-side request forgery in MCP tool validation endpointactivepiecesAttack Blocked by Atomicorp337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-8385WordPress WP Go Maps < 10.0.10 - Unauthenticated Marker Data Disclosurewp-google-mapsAttack Blocked by Atomicorp344365
CVE-2011-4898WordPress Core 3.3.1 - Multiple VulnerabilitiesWordPressAttack Blocked by Atomicorp340147 , 340148 , 344370 , 346755 , 381209 , 381210 , 390727 , 392301 , 392648
CVE-2013-6043Webuzo 2.1.3 - Multiple VulnerabilitieswebuzoAttack Blocked by Atomicorp333140 , 333141 , 340149 , 342259 , 344360 , 344361 , 344363 , 344370 , 346755 , 350148 , 390726 , 392647
CVE-2007-3385Apache Tomcat 6.0.15 - Cookie Quote Handling Remote Information DisclosuretomcatAttack Blocked by Atomicorp390727 , 392301 , 392648
CVE-2014-0871IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilitiesalgo credit limitsAttack Blocked by Atomicorp392301
CVE-2014-0894IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilitiesalgo credit limitsAttack Blocked by Atomicorp392301

Associated Atomicorp WAF Rules

RuleStatusBehavior
312863Activedisruptive (deny)
330791Activedisruptive (deny)
331028Activedisruptive (deny)
333140Activedisruptive (deny)
333141Activedisruptive (deny)
337109Activedisruptive (deny)
337110Activedisruptive (deny)
340007Activedisruptive (deny)
340014Activedisruptive (deny)
340016Activedisruptive (deny)
340017Activedisruptive (deny)
340023Activedisruptive (deny)
340029Activedisruptive (deny)
340077Activedisruptive (deny)
340087Activedisruptive (deny)
340095Activedisruptive (deny)
340144Activedisruptive (deny)
340147Activedisruptive (deny)
340148Activedisruptive (deny)
340149Activedisruptive (deny)
340152Activedisruptive (deny)
340155Activedisruptive (deny)
340156Activedisruptive (deny)
340157Activedisruptive (deny)
340159Activedisruptive (deny)
340162Activedisruptive (deny)
340163Activedisruptive (deny)
340165Activedisruptive (deny)
340193Activedisruptive (deny)
341145Activedisruptive (deny)
341155Activedisruptive (deny)
341245Activedisruptive (deny)
341256Activedisruptive (deny)
341266Activedisruptive (deny)
342259Activedisruptive (deny)
344360Activedisruptive (deny)
344361Activedisruptive (deny)
344363Activedisruptive (deny)
344364Activedisruptive (deny)
344365Activedisruptive (deny)
344366Activedisruptive (deny)
344370Activedisruptive (deny)
344372Activedisruptive (deny)
345240Activedisruptive (deny)
346755Activedisruptive (deny)
347009Activedisruptive (deny)
347019Activedisruptive (deny)
350147Activedisruptive (deny)
350148Activedisruptive (deny)
350590Activedisruptive (deny)
360147Activedisruptive (deny)
360148Activedisruptive (deny)
360153Activedisruptive (deny)
377360Activenon-disruptive (pass)
380018Activedisruptive (deny)
380026Activedisruptive (deny)
380122Activedisruptive (deny)
381209Activedisruptive (deny)
381210Activedisruptive (deny)
390585Activedisruptive (deny)
390613Activedisruptive (deny)
390614Activedisruptive (deny)
390703Activedisruptive (deny)
390704Activedisruptive (deny)
390709Activedisruptive (deny)
390716Activedisruptive (deny)
390719Activedisruptive (deny)
390720Activedisruptive (deny)
390722Activedisruptive (deny)
390724Activedisruptive (deny)
390726Activedisruptive (deny)
390727Activedisruptive (deny)
390904Activedisruptive (deny)
392301Activedisruptive (deny)
392647Activedisruptive (deny)
392648Activedisruptive (deny)
393655Activedisruptive (deny)
398021Activedisruptive (deny)
398022Activedisruptive (deny)

MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:

CAPEC-116 (opens in a new tab) , CAPEC-13 (opens in a new tab) , CAPEC-169 (opens in a new tab) , CAPEC-22 (opens in a new tab) , CAPEC-224 (opens in a new tab) , CAPEC-285 (opens in a new tab) , CAPEC-287 (opens in a new tab) , CAPEC-290 (opens in a new tab) , CAPEC-291 (opens in a new tab) , CAPEC-292 (opens in a new tab) , CAPEC-293 (opens in a new tab) , CAPEC-294 (opens in a new tab) , CAPEC-295 (opens in a new tab) , CAPEC-296 (opens in a new tab) , CAPEC-297 (opens in a new tab) , CAPEC-298 (opens in a new tab) , CAPEC-299 (opens in a new tab) , CAPEC-300 (opens in a new tab) , CAPEC-301 (opens in a new tab) , CAPEC-302 (opens in a new tab) , CAPEC-303 (opens in a new tab) , CAPEC-304 (opens in a new tab) , CAPEC-305 (opens in a new tab) , CAPEC-306 (opens in a new tab) , CAPEC-307 (opens in a new tab) , CAPEC-308 (opens in a new tab) , CAPEC-309 (opens in a new tab) , CAPEC-310 (opens in a new tab) , CAPEC-312 (opens in a new tab) , CAPEC-313 (opens in a new tab) , CAPEC-317 (opens in a new tab) , CAPEC-318 (opens in a new tab) , CAPEC-319 (opens in a new tab) , CAPEC-320 (opens in a new tab) , CAPEC-321 (opens in a new tab) , CAPEC-322 (opens in a new tab) , CAPEC-323 (opens in a new tab) , CAPEC-324 (opens in a new tab) , CAPEC-325 (opens in a new tab) , CAPEC-326 (opens in a new tab) , CAPEC-327 (opens in a new tab) , CAPEC-328 (opens in a new tab) , CAPEC-329 (opens in a new tab) , CAPEC-330 (opens in a new tab) , CAPEC-472 (opens in a new tab) , CAPEC-497 (opens in a new tab) , CAPEC-508 (opens in a new tab) , CAPEC-573 (opens in a new tab) , CAPEC-574 (opens in a new tab) , CAPEC-575 (opens in a new tab) , CAPEC-576 (opens in a new tab) , CAPEC-577 (opens in a new tab) , CAPEC-59 (opens in a new tab) , CAPEC-60 (opens in a new tab) , CAPEC-616 (opens in a new tab) , CAPEC-643 (opens in a new tab) , CAPEC-646 (opens in a new tab) , CAPEC-651 (opens in a new tab) , CAPEC-79 (opens in a new tab)