On this page
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Weakness Summary
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- Canonical source: MITRE CWE-200 (opens in a new tab)
- Published Atomicorp CVE observations: 81
- Distinct affected products in those observations: 73
- Active Atomicorp rules associated with this weakness: 79
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2026-51027 | FileThingie v.2.5.7 Information Disclosure Vulnerability | - | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2017-11165 | DataTaker DT80 dEX 1.50.012 - Information Disclosure | dt80 dex firmware | Attack Blocked by Atomicorp | 390716 |
| CVE-2018-0127 | Cisco RV132W/RV134W Router - Information Disclosure | rv132w firmware | Attack Blocked by Atomicorp | 312863 , 390716 |
| CVE-2018-15534 | Geutebrueck re_porter 7.8.974.20 - Credential Disclosure | re porter 16 firmware | Attack Blocked by Atomicorp | 390727 , 392301 , 392648 |
| CVE-2018-7251 | Anchor CMS 0.12.3 - Error Log Exposure | anchor | Attack Blocked by Atomicorp | 390716 |
| CVE-2026-65760 | Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0 | Easy Store extension for Joomla | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2020-9043 | WordPress wpCentral <1.5.1 - Information Disclosure | wpcentral | Detected by Atomicorp | 377360 |
| CVE-2021-32819 | Nodejs Squirrelly - Remote Code Execution | squirrelly | Attack Blocked by Atomicorp | 340014 , 340087 , 340095 , 340193 , 344370 , 345240 , 380026 |
| CVE-2026-47394 | PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate | PraisonAI | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2026-47743 | Shopper: Multiple data integrity and disclosure issues in admin Livewire components | shopper | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-62865 | TypeBot: Arbitrary server file read via Send Email block attachment path | typebot.io | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2018-16288 | LG SuperSign EZ CMS 2.5 - Local File Inclusion | supersign cms | Attack Blocked by Atomicorp | 347009 |
| CVE-2021-32820 | Express-handlebars - Local File Inclusion | express handlebars | Attack Blocked by Atomicorp | 344360 , 347009 , 390709 |
| CVE-2024-21136 | Oracle Retail Xstore Suite - Pre-authenticated Path Traversal | retail xstore office | Attack Blocked by Atomicorp | 340007 , 344365 , 347019 |
| CVE-2024-24919 | Check Point Quantum Gateway - Information Disclosure | quantum security gateway | Attack Blocked by Atomicorp | 392301 |
| CVE-2026-44881 | Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update | portainer | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2025-69755 | Neterbit NW-431F Router vNW-431F-20241014-IR03 Arbitrary Code Execution Vulnerability | - | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-39363 | Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket | vite | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2016-1337 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 firmware | Attack Blocked by Atomicorp | 333141 , 340147 , 340148 , 340149 , 341256 , 342259 , 344363 , 346755 , 350148 , 390726 , 392301 , 392647 , 392648 |
| CVE-2016-9314 | Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 - Multiple Vulnerabilities | interscan web security virtual appliance | Attack Blocked by Atomicorp | 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 , 390585 |
| CVE-2016-3473 | Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injection | business intelligence publisher | Attack Blocked by Atomicorp | 330791 , 340152 , 344370 , 344372 , 380018 , 390704 , 392301 |
| CVE-2026-53553 | Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise | goploy | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2014-8675 | SO Planning 1.32 - Multiple Vulnerabilities | soplanning | Attack Blocked by Atomicorp | 331028 , 340016 , 340017 , 340144 , 340155 , 340156 , 340157 , 340159 , 341155 , 341245 , 344363 , 344370 , 360147 , 360148 , 360153 , 390726 , 392647 |
| CVE-2014-9147 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | Attack Blocked by Atomicorp | 340007 , 340156 , 341145 , 344360 , 380026 , 380122 , 390709 , 390720 , 390726 , 392647 |
| CVE-2015-1000012 | WordPress MyPixs <=0.3 - Local File Inclusion | mypixs | Attack Blocked by Atomicorp | 344360 , 347009 , 390709 |
| CVE-2015-2080 | Inductive Automation Ignition 7.8.1 - Remote Leakage Of Shared Buffers | fedora | Attack Blocked by Atomicorp | 344361 , 344363 , 344364 , 344365 , 390724 |
| CVE-2016-4806 | Web2py 2.14.5 - Multiple Vulnerabilities | web2py | Attack Blocked by Atomicorp | 344360 , 344364 , 344366 , 344370 |
| CVE-2016-5677 | NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities | readynas surveillance | Attack Blocked by Atomicorp | 392301 |
| CVE-2017-1000029 | Oracle GlassFish Server Open Source Edition 3.0.1 - Local File Inclusion | glassfish server | Attack Blocked by Atomicorp | 347009 |
| CVE-2017-16894 | Laravel <5.5.21 - Information Disclosure | laravel | Attack Blocked by Atomicorp | 390709 |
| CVE-2017-9812 | Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilities | anti-virus for linux server | Attack Blocked by Atomicorp | 390704 , 390724 |
| CVE-2018-1306 | Apache Portals Pluto 3.0.0 - Remote Code Execution | pluto | Attack Blocked by Atomicorp | 390727 , 392648 |
| CVE-2018-3760 | Ruby On Rails - Local File Inclusion | cloudforms | Attack Blocked by Atomicorp | 347009 |
| CVE-2018-6008 | Joomla! Jtag Members Directory 5.3.7 - Local File Inclusion | jtag members directory | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2018-8033 | Apache OFBiz - XML External Entity Injection | ofbiz | Attack Blocked by Atomicorp | 341256 , 344370 , 344372 |
| CVE-2021-24170 | User Profile Picture < 2.5.0 - Sensitive Information Disclosure | user profile picture | Detected by Atomicorp | 377360 |
| CVE-2021-24227 | Patreon WordPress <1.7.0 - Unauthenticated Local File Inclusion | patreon wordpress | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2021-41277 | Metabase - Local File Inclusion | metabase | Attack Blocked by Atomicorp | 340165 , 344360 , 347009 |
| CVE-2021-43287 | Pre-Auth Takeover of Build Pipelines in GoCD | gocd | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2023-34092 | Vite Dev Server - Information Exposure | vite | Attack Blocked by Atomicorp | 390709 |
| CVE-2023-40211 | Post Grid <= 2.2.50 - Information Exposure via REST API | post grid combo | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2023-40600 | EWWW Image Optimizer <= 7.2.0 - Unauthenticated Information Disclosure | image optimizer | Attack Blocked by Atomicorp | 390716 |
| CVE-2023-44982 | WordPress Perfect Images (WP Retina 2x) < 6.4.6 - Sensitive Information Exposure | perfect images | Attack Blocked by Atomicorp | 390716 |
| CVE-2024-12008 | W3 Total Cache < 2.8.2 - Log File Exposure | w3 total cache | Attack Blocked by Atomicorp | 390716 |
| CVE-2024-45388 | Hoverfly < 1.10.3 - Arbitrary File Read | hoverfly | Attack Blocked by Atomicorp | 344360 , 390709 |
| CVE-2024-46938 | Sitecore Experience Platform <= 10.4 - Arbitrary File Read | experience commerce | Attack Blocked by Atomicorp | 340007 , 344360 , 344365 , 347019 , 390709 |
| CVE-2025-30208 | Vite - Arbitrary File Read | vite | Attack Blocked by Atomicorp | 347009 , 390709 |
| CVE-2025-31125 | Vite Development Server - Path Traversal | vite | Attack Blocked by Atomicorp | 347009 , 390709 , 390716 |
| CVE-2026-51078 | Dede CMS v.5.7.118 Information Disclosure Vulnerability | - | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-61891 | theia Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | theia | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-47735 | Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks | arc | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 , 390719 |
| CVE-2024-7339 | TVT DVR Sensitive Device - Information Disclosure | sh-4050a5-5l(mm) firmware | Attack Blocked by Atomicorp | 392301 |
| CVE-2014-2383 | Dompdf < v0.6.0 - Local File Inclusion | dompdf | Attack Blocked by Atomicorp | 340077 , 340165 , 344360 , 347009 |
| CVE-2015-4682 | Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities | realpresence resource manager | Attack Blocked by Atomicorp | 330791 , 340152 , 392301 |
| CVE-2016-6435 | Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusion | secure firewall management center | Attack Blocked by Atomicorp | 340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709 |
| CVE-2018-18762 | SaltOS Erp Crm 3.1 r8126 - Database File Download | saltos | Attack Blocked by Atomicorp | 390716 |
| CVE-2021-22145 | Elasticsearch 7.10.0-7.13.3 - Information Disclosure | elasticsearch | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2022-34125 | GLPI Activity v3.1.0 - Authenticated Local File Inclusion on Activity plugin | cmdb | Attack Blocked by Atomicorp | 340007 , 344360 |
| CVE-2026-58442 | Repository migration SSRF via multi-answer DNS allow-list bypass | Gitea Open Source Git Server | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-29066 | TinaCMS - Path Traversal | tinacms | Attack Blocked by Atomicorp | 347009 , 390709 |
| CVE-2017-14955 | Check_MK 1.2.8p25 - Information Disclosure | checkmk | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2024-13609 | WordPress 1 Click Migration Plugin < 2.3 - Information Exposure | 1 click migration | Attack Blocked by Atomicorp | 350590 , 390716 |
| CVE-2025-14528 | D-Link DIR-803 - Authentication Bypass | dir-803 firmware | Attack Blocked by Atomicorp | 390722 |
| CVE-2018-8024 | Apache Spark UI - Cross-Site Scripting | spark | Attack Blocked by Atomicorp | 340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2013-2683 | Cisco Linksys E4200 - Multiple Vulnerabilities | linksys e4200 firmware | Attack Blocked by Atomicorp | 392301 |
| CVE-2015-2826 | WordPress Plugin Simple Ads Manager - Information Disclosure | simple ads manager | Attack Blocked by Atomicorp | 344370 , 390904 |
| CVE-2016-1910 | SAP NetWeaver J2EE Engine 7.40 - SQL Injection | netweaver | Attack Blocked by Atomicorp | 340016 , 340156 , 341245 , 380026 , 390704 |
| CVE-2016-2388 | SAP NetWeaver J2EE Engine 7.40 - SQL Injection | netweaver application server java | Attack Blocked by Atomicorp | 340016 , 340156 , 341245 , 380026 , 390704 |
| CVE-2017-9978 | QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities | quantastor | Attack Blocked by Atomicorp | 330791 , 340152 , 392301 |
| CVE-2021-34429 | Eclipse Jetty 11.0.5 - Sensitive File Disclosure | jetty | Attack Blocked by Atomicorp | 390703 |
| CVE-2024-8852 | All-in-One WP Migration < 7.87 - Unauthenticated Information Disclosure | all-in-one wp migration | Attack Blocked by Atomicorp | 390716 |
| CVE-2025-11368 | LearnPress < 4.3.0 - Arbitrary Callback Execution to Information Exposure | learnpress | Attack Blocked by Atomicorp | 344365 |
| CVE-2025-31486 | Vite server.fs.deny Bypass - Local File Inclusion | vite | Attack Blocked by Atomicorp | 347009 , 390709 |
| CVE-2026-53452 | Ground Station: Unauthenticated out-of-containment file read via sigmfplayback recordingPath | ground-station | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2026-73082 | Activepieces: Server-side request forgery in MCP tool validation endpoint | activepieces | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-8385 | WordPress WP Go Maps < 10.0.10 - Unauthenticated Marker Data Disclosure | wp-google-maps | Attack Blocked by Atomicorp | 344365 |
| CVE-2011-4898 | WordPress Core 3.3.1 - Multiple Vulnerabilities | WordPress | Attack Blocked by Atomicorp | 340147 , 340148 , 344370 , 346755 , 381209 , 381210 , 390727 , 392301 , 392648 |
| CVE-2013-6043 | Webuzo 2.1.3 - Multiple Vulnerabilities | webuzo | Attack Blocked by Atomicorp | 333140 , 333141 , 340149 , 342259 , 344360 , 344361 , 344363 , 344370 , 346755 , 350148 , 390726 , 392647 |
| CVE-2007-3385 | Apache Tomcat 6.0.15 - Cookie Quote Handling Remote Information Disclosure | tomcat | Attack Blocked by Atomicorp | 390727 , 392301 , 392648 |
| CVE-2014-0871 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | Attack Blocked by Atomicorp | 392301 |
| CVE-2014-0894 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | Attack Blocked by Atomicorp | 392301 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 312863 | Active | disruptive (deny) |
| 330791 | Active | disruptive (deny) |
| 331028 | Active | disruptive (deny) |
| 333140 | Active | disruptive (deny) |
| 333141 | Active | disruptive (deny) |
| 337109 | Active | disruptive (deny) |
| 337110 | Active | disruptive (deny) |
| 340007 | Active | disruptive (deny) |
| 340014 | Active | disruptive (deny) |
| 340016 | Active | disruptive (deny) |
| 340017 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340029 | Active | disruptive (deny) |
| 340077 | Active | disruptive (deny) |
| 340087 | Active | disruptive (deny) |
| 340095 | Active | disruptive (deny) |
| 340144 | Active | disruptive (deny) |
| 340147 | Active | disruptive (deny) |
| 340148 | Active | disruptive (deny) |
| 340149 | Active | disruptive (deny) |
| 340152 | Active | disruptive (deny) |
| 340155 | Active | disruptive (deny) |
| 340156 | Active | disruptive (deny) |
| 340157 | Active | disruptive (deny) |
| 340159 | Active | disruptive (deny) |
| 340162 | Active | disruptive (deny) |
| 340163 | Active | disruptive (deny) |
| 340165 | Active | disruptive (deny) |
| 340193 | Active | disruptive (deny) |
| 341145 | Active | disruptive (deny) |
| 341155 | Active | disruptive (deny) |
| 341245 | Active | disruptive (deny) |
| 341256 | Active | disruptive (deny) |
| 341266 | Active | disruptive (deny) |
| 342259 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344364 | Active | disruptive (deny) |
| 344365 | Active | disruptive (deny) |
| 344366 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 344372 | Active | disruptive (deny) |
| 345240 | Active | disruptive (deny) |
| 346755 | Active | disruptive (deny) |
| 347009 | Active | disruptive (deny) |
| 347019 | Active | disruptive (deny) |
| 350147 | Active | disruptive (deny) |
| 350148 | Active | disruptive (deny) |
| 350590 | Active | disruptive (deny) |
| 360147 | Active | disruptive (deny) |
| 360148 | Active | disruptive (deny) |
| 360153 | Active | disruptive (deny) |
| 377360 | Active | non-disruptive (pass) |
| 380018 | Active | disruptive (deny) |
| 380026 | Active | disruptive (deny) |
| 380122 | Active | disruptive (deny) |
| 381209 | Active | disruptive (deny) |
| 381210 | Active | disruptive (deny) |
| 390585 | Active | disruptive (deny) |
| 390613 | Active | disruptive (deny) |
| 390614 | Active | disruptive (deny) |
| 390703 | Active | disruptive (deny) |
| 390704 | Active | disruptive (deny) |
| 390709 | Active | disruptive (deny) |
| 390716 | Active | disruptive (deny) |
| 390719 | Active | disruptive (deny) |
| 390720 | Active | disruptive (deny) |
| 390722 | Active | disruptive (deny) |
| 390724 | Active | disruptive (deny) |
| 390726 | Active | disruptive (deny) |
| 390727 | Active | disruptive (deny) |
| 390904 | Active | disruptive (deny) |
| 392301 | Active | disruptive (deny) |
| 392647 | Active | disruptive (deny) |
| 392648 | Active | disruptive (deny) |
| 393655 | Active | disruptive (deny) |
| 398021 | Active | disruptive (deny) |
| 398022 | Active | disruptive (deny) |
Related MITRE CAPEC Context
MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:
CAPEC-116 (opens in a new tab) , CAPEC-13 (opens in a new tab) , CAPEC-169 (opens in a new tab) , CAPEC-22 (opens in a new tab) , CAPEC-224 (opens in a new tab) , CAPEC-285 (opens in a new tab) , CAPEC-287 (opens in a new tab) , CAPEC-290 (opens in a new tab) , CAPEC-291 (opens in a new tab) , CAPEC-292 (opens in a new tab) , CAPEC-293 (opens in a new tab) , CAPEC-294 (opens in a new tab) , CAPEC-295 (opens in a new tab) , CAPEC-296 (opens in a new tab) , CAPEC-297 (opens in a new tab) , CAPEC-298 (opens in a new tab) , CAPEC-299 (opens in a new tab) , CAPEC-300 (opens in a new tab) , CAPEC-301 (opens in a new tab) , CAPEC-302 (opens in a new tab) , CAPEC-303 (opens in a new tab) , CAPEC-304 (opens in a new tab) , CAPEC-305 (opens in a new tab) , CAPEC-306 (opens in a new tab) , CAPEC-307 (opens in a new tab) , CAPEC-308 (opens in a new tab) , CAPEC-309 (opens in a new tab) , CAPEC-310 (opens in a new tab) , CAPEC-312 (opens in a new tab) , CAPEC-313 (opens in a new tab) , CAPEC-317 (opens in a new tab) , CAPEC-318 (opens in a new tab) , CAPEC-319 (opens in a new tab) , CAPEC-320 (opens in a new tab) , CAPEC-321 (opens in a new tab) , CAPEC-322 (opens in a new tab) , CAPEC-323 (opens in a new tab) , CAPEC-324 (opens in a new tab) , CAPEC-325 (opens in a new tab) , CAPEC-326 (opens in a new tab) , CAPEC-327 (opens in a new tab) , CAPEC-328 (opens in a new tab) , CAPEC-329 (opens in a new tab) , CAPEC-330 (opens in a new tab) , CAPEC-472 (opens in a new tab) , CAPEC-497 (opens in a new tab) , CAPEC-508 (opens in a new tab) , CAPEC-573 (opens in a new tab) , CAPEC-574 (opens in a new tab) , CAPEC-575 (opens in a new tab) , CAPEC-576 (opens in a new tab) , CAPEC-577 (opens in a new tab) , CAPEC-59 (opens in a new tab) , CAPEC-60 (opens in a new tab) , CAPEC-616 (opens in a new tab) , CAPEC-643 (opens in a new tab) , CAPEC-646 (opens in a new tab) , CAPEC-651 (opens in a new tab) , CAPEC-79 (opens in a new tab)