CWE-315: Cleartext Storage of Sensitive Information in a Cookie
The product stores sensitive information in cleartext in a cookie.
6 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-24768 — 1Panel set-cookie is missing the Secure keyword
- CVE-2025-8528 — Exrick xboot getMenuList sensitive information in a cookie
- CVE-2025-4537 — yangzongzhuan RuoYi-Vue Password login.vue sensitive information in a cookie
Recently published
- CVE-2025-8528 — Exrick xboot getMenuList sensitive information in a cookie
- CVE-2025-4537 — yangzongzhuan RuoYi-Vue Password login.vue sensitive information in a cookie
- CVE-2024-24768 — 1Panel set-cookie is missing the Secure keyword