Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-1004

Sensitive Cookie Without 'HttpOnly' Flag

The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.

42
Assigned CVEs
242nd
Commonality Rank
6.4
Avg CVSS
0.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-1004 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 7, 2019
7 years ago
Most Recent CVE
Jun 29, 2026
25 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

42 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-27223HIGH
TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the applica
Oct 27, 20257.541NOYES
CVE-2026-42239HIGH
Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-co
May 7, 20268.132NONO
CVE-2026-57948MEDIUM
Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secu
Jun 29, 20266.831NONO
CVE-2021-42115CRITICAL
Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privi
Nov 30, 20219.129NONO
CVE-2025-26844CRITICAL
An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.
May 8, 20259.828NONO
CVE-2026-35575HIGH
ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s group-creation feature allows an
Apr 7, 20268.027NONO
CVE-2025-47289CRITICAL
CE Phoenix is a free, open-source eCommerce platform. A stored cross-site scripting (XSS) vulnerability was discovered in CE Phoenix versions 1.0.9.9 through 1.1.0.2 where an attac
Jun 2, 20259.027NONO
CVE-2026-0696MEDIUM
In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to s
Jan 16, 20266.526NONO
CVE-2026-22081HIGH
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the
Jan 9, 20268.825NONO
CVE-2025-57424HIGH
A stored cross-site scripting (XSS) vulnerability exists in the MyCourts v3 application within the LTA number profile field. An attacker can insert arbitrary JavaScript into their
Sep 29, 20257.324NONO
View all 42 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
10%
4.0-4.9
14%
19%
5.0-5.9
36%
16%
6.0-6.9
14%
26%
7.0-7.9
12%
11%
8.0-8.9
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.4% of CVEs· 91st percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products