CWE-1004
35 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1004page 1 of 1
- CVE-2019-25091LOWCVSS 3.7EG 5.32022-12-27
A vulnerability classified as problematic has been found in nsupdate.info. This affects an unknown part of the file src/nsupdate/settings/base.py of the component CSRF Cookie Handler. The manipulation of the argument CSRF_COOKIE_HTTPONLY l…
- CVE-2019-8283MEDIUMCVSS 6.5EG 6.52019-06-07
Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it.
- CVE-2020-27658HIGHCVSS 7.1EG 7.12020-10-29
Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to t…
- CVE-2020-6267MEDIUMCVSS 5.4EG 5.42020-07-14
Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag.
- CVE-2021-34563LOWCVSS 3.3EG 3.32021-08-31
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript.
- CVE-2021-3706HIGHCVSS 7.5EG 7.52021-09-15
adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag
- CVE-2021-39210MEDIUMCVSS 6.5EG 6.52021-09-15
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal t…
- CVE-2021-42115HIGHCVSS 8.1EG 8.12021-11-30
Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privileges from unauthenticated to authenticated user via ste…
- CVE-2022-21939HIGHCVSS 7.5EG 6.12023-02-09
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
- CVE-2022-25172MEDIUMCVSS 6.1EG 6.12022-05-12
An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and thus allowing an a…
- CVE-2022-33167LOWCVSS 3.7EG 3.72024-07-30
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this…
- CVE-2022-43845LOWCVSS 3.7EG 3.72024-09-25
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from t…
- CVE-2022-4630MEDIUMCVSS 5.3EG 5.32022-12-21
Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master.
- CVE-2023-2876LOWCVSS 3.1EG 3.12023-06-13
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0…
- CVE-2023-4217LOWCVSS 3.1EG 3.12023-11-02
A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user sess…
- CVE-2023-4228LOWCVSS 3.1EG 3.12023-08-24
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks,…
- CVE-2024-41685HIGHCVSS 7.5EG 7.52024-07-26
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit this by intercepting t…
- CVE-2024-47833MEDIUMCVSS 6.5EG 6.52024-10-09
Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. This issue has been …
- CVE-2024-6739MEDIUMCVSS 5.3EG 5.32024-07-15
The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.
- CVE-2025-0479HIGHCVSS 8.6EG 0.02025-01-20
This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface. A remote attacker could exploit this vulnerability by intercepting data transmissions during an HTTP session on the vul…
- CVE-2025-12031MEDIUMCVSS 5.3EG 5.32025-10-21
HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the javascript contextThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
- CVE-2025-24318MEDIUMCVSS 6.8EG 6.82025-02-28
Cookie policy is observable via built-in browser tools. In the presence of XSS, this could lead to full session compromise.
- CVE-2025-26844CRITICALCVSS 9.8EG 9.82025-05-08
An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.
- CVE-2025-27223HIGHCVSS 7.5EG 7.52025-10-27
TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ulti…
- CVE-2025-27453MEDIUMCVSS 5.3EG 5.32025-07-03
The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such as JavaScript.
- CVE-2025-42909LOWCVSS 3.0EG 3.02025-10-14
SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentia…
- CVE-2025-47289MEDIUMCVSS 6.3EG 6.32025-06-02
CE Phoenix is a free, open-source eCommerce platform. A stored cross-site scripting (XSS) vulnerability was discovered in CE Phoenix versions 1.0.9.9 through 1.1.0.2 where an attacker can inject malicious JavaScript into the testimonial de…
- CVE-2025-49189MEDIUMCVSS 5.3EG 5.32025-06-12
The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scripting attacks which tar…
- CVE-2025-53757HIGHCVSS 8.7EG 0.02025-07-16
This vulnerability exists in Digisol DG-GR6821AC Router due to misconfiguration of both Secure and HttpOnly flags on session cookies associated with the router web interface. A remote attacker could exploit this vulnerability by capturing …
- CVE-2025-57424HIGHCVSS 7.3EG 7.32025-09-29
A stored cross-site scripting (XSS) vulnerability exists in the MyCourts v3 application within the LTA number profile field. An attacker can insert arbitrary JavaScript into their profile, which executes in the browser of any user viewing …
- CVE-2026-0696MEDIUMCVSS 6.5EG 6.52026-01-16
In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values.
- CVE-2026-22081HIGHCVSS 8.8EG 0.02026-01-09
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker cou…
- CVE-2026-35575HIGHCVSS 8.0EG 8.02026-04-07
ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s group-creation feature allows any user with group-creation privileges to inject malicious…
- CVE-2026-39338MEDIUMCVSS 6.1EG 6.12026-04-07
ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerability exists in the search parameter accepted by the ChurchCRM dashboard. The application fails to sanitize or encode user…
- CVE-2026-42239HIGHCVSS 8.1EG 8.12026-05-07
Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.ts:218. JavaScript can read this cookie …
Map vulnerabilities like CWE-1004 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1004 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →