CWE-565— Reliance on Cookies without Validation and Integrity Checking
71 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-565page 2 of 2
- CVE-2024-1551MEDIUMCVSS 6.1EG 6.12024-02-20
Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response head…
- CVE-2024-21583MEDIUMCVSS 4.1EG 4.12024-07-19
Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/components/ws-proxy/pkg/proxy before main-gha.27122; versions of the package github…
- CVE-2024-21872HIGHCVSS 7.5EG 7.52024-04-18
The device allows an unauthenticated attacker to bypass authentication and modify the cookie to reveal hidden pages that allows more critical operations to the transmitter.
- CVE-2024-22186HIGHCVSS 8.8EG 8.82024-04-18
The application suffers from a privilege escalation vulnerability. An attacker logged in as guest can escalate his privileges by poisoning the cookie to become administrator.
- CVE-2024-28233HIGHCVSS 8.1EG 8.12024-03-27
JupyterHub is an open source multi-user server for Jupyter notebooks. By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of Jupyte…
- CVE-2024-28288CRITICALCVSS 9.8EG 9.82024-03-30
Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vulnerability. An attacker can use this vulnerability to log in to the device and disrupt the business…
- CVE-2024-39734MEDIUMCVSS 4.3EG 4.32024-07-14
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting thi…
- CVE-2024-55211HIGHCVSS 8.4EG 8.42025-04-17
An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.
- CVE-2024-9820MEDIUMCVSS 6.5EG 6.52024-10-15
The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-facto…
- CVE-2024-9970HIGHCVSS 8.8EG 8.82024-10-15
The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie.
- CVE-2025-14440CRITICALCVSS 9.8EG 9.82025-12-13
The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.01. This is due to incorrect authentication checking in the 'jay_login_register_process_switch_back' function with t…
- CVE-2025-2395CRITICALCVSS 9.8EG 9.82025-03-17
The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to use a particular API and alter cookies to log in as an administrator.
- CVE-2025-31120MEDIUMCVSS 5.3EG 5.32025-04-18
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, an insecure view count mechanism in the forum page allows an unauthenticated attacker to artificially increase the view count.…
- CVE-2025-48980MEDIUMCVSS 6.5EG 6.52025-10-31
In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on …
- CVE-2025-59247HIGHCVSS 8.8EG 8.82025-10-09
Azure PlayFab Elevation of Privilege Vulnerability
- CVE-2025-64447HIGHCVSS 8.1EG 8.12025-12-09
A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.…
- CVE-2025-65212CRITICALCVSS 9.8EG 9.82026-01-06
An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the device's insufficient cookie verification, allowing an attacker to directly request the configuration file address and dow…
- CVE-2026-0257CRITICALCVSS 9.1EG 9.1⚠ KEV2026-05-13
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGF…
- CVE-2026-39324CRITICALCVSS 9.8EG 9.82026-04-07
Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secrets:. If cookie decryption fails, the implementation falls ba…
- CVE-2026-39963MEDIUMCVSS 6.9EG 6.92026-04-15
Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the serendipity_setCookie() function in include/functions_config.inc.php uses $_SERVER['HTTP_HOST'] without validation as the domain parameter of setcookie(). An…
- CVE-2026-8337MEDIUMCVSS 5.3EG 5.32026-05-21
Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public and private surveys are present on the site. An unauthenticated attacker can vote in the …
Map vulnerabilities like CWE-565 to your infrastructure
EchelonGraph correlates every CVE — across CWE-565 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →