CWE-1275: Sensitive Cookie with Improper SameSite Attribute
The SameSite attribute for sensitive cookies is not set, or an insecure value is used.
26 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-24897 — Misskey CSRF vulnerability due to insecure configuration of authentication cookie attributes
- CVE-2026-73847 — Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover
- CVE-2024-42212 — HCL BigFix Compliance is affected by an improper or missing SameSite attribute
- CVE-2026-1697 — Use of unsecure cookies for GraphicalData web service and WebClient web app
- CVE-2025-24387 — Missing CSRF protection
- CVE-2025-52628 — HCL AION is susceptible to Missing SameSite vulnerability
- CVE-2026-81888 — @hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking
- CVE-2025-36134 — IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
- CVE-2024-43173 — IBM Concert information disclosure
- CVE-2026-55688 — AsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via ThreadSafeCookieStore
- CVE-2026-8435 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion()
- CVE-2026-8434 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple()
- CVE-2026-8433 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan()
- CVE-2026-8432 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star()
- CVE-2026-8427 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id)
- CVE-2026-8416 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id)
- CVE-2026-8415 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder
- CVE-2026-8414 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate
- CVE-2026-8413 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design
- CVE-2026-8412 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache
Recently published
- CVE-2026-81888 — @hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking
- CVE-2026-73847 — Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover
- CVE-2026-55688 — AsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via ThreadSafeCookieStore
- CVE-2026-8409 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete
- CVE-2026-8410 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete
- CVE-2026-8411 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete
- CVE-2026-8412 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache
- CVE-2026-8413 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design
- CVE-2026-8414 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate
- CVE-2026-8415 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder
- CVE-2026-8416 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id)
- CVE-2026-8427 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id)
- CVE-2026-8432 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star()
- CVE-2026-8433 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan()
- CVE-2026-8434 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple()
- CVE-2026-8435 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion()
- CVE-2026-1697 — Use of unsecure cookies for GraphicalData web service and WebClient web app
- CVE-2025-52628 — HCL AION is susceptible to Missing SameSite vulnerability
- CVE-2025-36134 — IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
- CVE-2024-42212 — HCL BigFix Compliance is affected by an improper or missing SameSite attribute