CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag

The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.

41 tracked CVEs are classified under this weakness.

Highest-risk vulnerabilities

Recently published

Browse the full CVE database