The web application uses persistent cookies, but the cookies contain sensitive information.
Volume of CVEs assigned to CWE-539 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35192MEDIUM An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.
Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. | May 5, 2026 | 6.5 | 27 | NO | NO |
CVE-2024-39275HIGH Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a
session is closed. Forging requests with a legitimate cookie, even if
the session was ter | Sep 27, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-30861HIGH Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequent | May 2, 2023 | 7.5 | 25 | NO | NO |
CVE-2025-27673CRITICAL Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cookie Returned in Response Body OVE-20230524-0017. | Mar 5, 2025 | 9.1 | 24 | NO | NO |
CVE-2021-27463MEDIUM A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications utilize persistent cookies where the session cookie attri | May 20, 2021 | 5.3 | 19 | NO | NO |
CVE-2026-24318MEDIUM Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthenticated attacker could obtain valid session tokens and reuse | Apr 14, 2026 | 4.2 | 18 | NO | NO |
CVE-2025-52633MEDIUM HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensitive session data in persistent cookies may increase the risk | Feb 3, 2026 | 5.3 | 18 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.