VYPR

CWE-1004

Sensitive Cookie Without 'HttpOnly' Flag

VariantIncompleteLikelihood: Medium

Description

The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (44)

page 1 of 3
  • CVE-2025-26844CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.

  • CVE-2026-22081HigJan 9, 2026
    risk 0.57cvss epss 0.00

    This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker could exploit this vulnerability by…

  • CVE-2025-53757HigJul 16, 2025
    risk 0.57cvss epss 0.00

    This vulnerability exists in Digisol DG-GR6821AC Router due to misconfiguration of both Secure and HttpOnly flags on session cookies associated with the router web interface. A remote attacker could exploit this vulnerability by capturing the session cookies transmitted over an…

  • CVE-2025-0479HigJan 20, 2025
    risk 0.56cvss epss 0.00

    This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface. A remote attacker could exploit this vulnerability by intercepting data transmissions during an HTTP session on the vulnerable system. Successful…

  • CVE-2021-42115HigNov 30, 2021
    risk 0.53cvss 8.1epss 0.01

    Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privileges from unauthenticated to authenticated user via stealing and injecting the session-…

  • CVE-2025-27223HigOct 27, 2025
    risk 0.49cvss 7.5epss 0.02

    TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing anyone to forge cookies…

  • CVE-2024-41685HigJul 26, 2024
    risk 0.49cvss 7.5epss 0.01

    This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit this by intercepting transmission within an HTTP session on…

  • CVE-2022-21939HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.

  • CVE-2025-57424HigSep 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in the MyCourts v3 application within the LTA number profile field. An attacker can insert arbitrary JavaScript into their profile, which executes in the browser of any user viewing it, including administrators. Due to the…

  • CVE-2026-42239HigMay 7, 2026
    risk 0.46cvss 8.1epss 0.00

    Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.ts:218. JavaScript can read this cookie via document.cookie. This means every…

  • CVE-2026-25136HigFeb 25, 2026
    risk 0.46cvss 8.1epss 0.00

    Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. A reflected Cross-site Scripting vulnerability was located in versions prior to 35.8.3, 38.5.4, and 39.3.1 in the rendering of…

  • CVE-2020-27658HigOct 29, 2020
    risk 0.46cvss 7.1epss 0.01

    Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

  • CVE-2026-53660higAug 14, 2026
    risk 0.45cvss epss

    ## Summary **Description** An Insecure Default Initialization of Resource (CWE-1188) issue in the OpenAM default configuration ships the `iPlanetDirectoryPro` SSO cookie with `HttpOnly=false`. Also, the `iPlanetDirectoryPro` SSO cookie is used as a CSRF token in OAuth/OIDC…

  • CVE-2026-35575HigApr 7, 2026
    risk 0.45cvss 8.0epss 0.00

    ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s group-creation feature allows any user with group-creation privileges to inject malicious JavaScript that executes automatically…

  • CVE-2025-24318MedFeb 28, 2025
    risk 0.44cvss 6.8epss 0.00

    Cookie policy is observable via built-in browser tools. In the presence of XSS, this could lead to full session compromise.

  • CVE-2026-0696MedJan 16, 2026
    risk 0.42cvss 6.5epss 0.00

    In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values.

  • CVE-2024-47833MedOct 9, 2024
    risk 0.42cvss 6.5epss 0.00

    Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. This issue has been addressed in release version 4.0.0 and…

  • CVE-2021-39210MedSep 15, 2021
    risk 0.42cvss 6.5epss 0.01

    GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal this cookie would be able to use it to…

  • CVE-2019-8283MedJun 7, 2019
    risk 0.42cvss 6.5epss 0.01

    Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it.

  • CVE-2025-47289MedJun 2, 2025
    risk 0.41cvss 6.3epss 0.00

    CE Phoenix is a free, open-source eCommerce platform. A stored cross-site scripting (XSS) vulnerability was discovered in CE Phoenix versions 1.0.9.9 through 1.1.0.2 where an attacker can inject malicious JavaScript into the testimonial description field. Once submitted, if the…