CWE-1004Variant

Sensitive Cookie Without 'HttpOnly' Flag

Incomplete in the CWE catalog · 41 CVEs mapped

41
CVEs mapped
6.3
Median CVSS
What it is

The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.

Recent examples
3.7cvss
CVE-2026-82697

CVE-2026-82697 - LOW Severity Vulnerability

A security vulnerability has been detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The impacted element is the function session_start. Such manipulation leads to cookie without 'httponly' flag. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitability is regarded as difficult. The exploit has been disclosed publicly and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.

LOWno explanation yet
0%
epss
5.4cvss
CVE-2026-21754

CVE-2026-21754 - MEDIUM Severity Vulnerability

HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within internal communications.

MEDIUMno explanation yet
0%
epss
7.6cvss
CVE-2026-57948

Pinpoint - Insecure Session Cookie Attributes in pinpointJwt

Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP. Attackers can exploit stored or reflected cross-site scripting vulnerabilities to exfiltrate the session token or intercept it through network sniffing to perform session hijacking.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1004
Abstraction
Variant
Structure
Simple
Status
Incomplete
References (5)