CVE-2026-39570
Insertion of Sensitive Information Into Sent Data vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Retrieve
CVSS
5.3
Medio
EPSS
0.2%
p15
KEV
—
Exploit Today
4
0-100
Publicado: 8 abr 2026 · Última mod.: 24 jul 2026 · CWE-201
0.2%EPSS · 30 días0.2%
2026-07-292026-08-26
Insertion of Sensitive Information Into Sent Data vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Retrieve Embedded Sensitive Data.This issue affects 12 Step Meeting List: from n/a through <= 3.19.9.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-665857.5 ALT15.5%
——5Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.3dCVE-2026-598094.9 MED15.3%
——5SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plaintext secret values to any public host without confirmation.5dCVE-2026-63481—38.5%
——12Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier, the redirect handling in packages/hurl/src/http/client.rs strips Authorization and Cookie headers and basic-auth credentials when a redirect changes host, but it carries RequestSpec.cookies created from the dedicated [Cookies] section into the redirected request. An attacker-controlled redirect can therefore receive authentication or session cookies that should remain scoped to the original host. Cookies supplied through a raw Cookie header are stripped and are not affected by this specific path. This issue is reported as fixed in version 8.1.0.6dCVE-2026-759537.5 ALT4.4%
——1Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.1dCVE-2026-733867.5 ALT15.5%
——5Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.7dCVE-2026-733847.5 ALT15.5%
——5Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.7d