CWE-202: Exposure of Sensitive Information Through Data Queries
When trying to keep information confidential, an attacker can often infer some of the information by using statistics.
Last updated
Overview
In situations where data should not be tied to individual users, but a large number of users should be able to make queries that "scrub" the identity of users, it may be possible to get information about a user -- e.g., by specifying search terms that are known to be unique to that user.
Real-world CVEs
31 recorded CVEs are caused by CWE-202 (Exposure of Sensitive Information Through Data Queries). The highest-severity and most recent are shown first. 5 new CWE-202 CVEs have been recorded so far in 2026 (8 in 2025).
- CVE-2021-32743High · CVSS 8.82021-07-15
- CVE-2024-2088
NextScripts: Social Networks Auto-Poster <= 4.4.3 - Authenticated(Subscriber+) Sensitive Information Exposure
High · CVSS 8.52024-05-22 - CVE-2025-25205
Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matching
High · CVSS 8.2