The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.
Volume of CVEs assigned to CWE-1004 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-27223HIGH TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the applica | Oct 27, 2025 | 7.5 | 41 | NO | YES |
CVE-2026-42239HIGH Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-co | May 7, 2026 | 8.1 | 32 | NO | NO |
CVE-2026-57948MEDIUM Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secu | Jun 29, 2026 | 6.8 | 31 | NO | NO |
CVE-2021-42115CRITICAL Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privi | Nov 30, 2021 | 9.1 | 29 | NO | NO |
CVE-2025-26844CRITICAL An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag. | May 8, 2025 | 9.8 | 28 | NO | NO |
CVE-2026-35575HIGH ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s group-creation feature allows an | Apr 7, 2026 | 8.0 | 27 | NO | NO |
CVE-2025-47289CRITICAL CE Phoenix is a free, open-source eCommerce platform. A stored cross-site scripting (XSS) vulnerability was discovered in CE Phoenix versions 1.0.9.9 through 1.1.0.2 where an attac | Jun 2, 2025 | 9.0 | 27 | NO | NO |
CVE-2026-0696MEDIUM In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to s | Jan 16, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-22081HIGH This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the | Jan 9, 2026 | 8.8 | 25 | NO | NO |
CVE-2025-57424HIGH A stored cross-site scripting (XSS) vulnerability exists in the MyCourts v3 application within the LTA number profile field. An attacker can insert arbitrary JavaScript into their | Sep 29, 2025 | 7.3 | 24 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.