CWE-784: Reliance on Cookies without Validation and Integrity Checking in a Security Decision
The product uses a protection mechanism that relies on the existence or values of a cookie, but it does not properly ensure that the cookie is valid for the associated user.
6 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-60134 — Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Security Decision
- CVE-2026-45055 — CubeCart: Pre-Authenticated Password Reset Link Poisoning via HTTP Host Header
- CVE-2024-9820 — WP 2FA with Telegram <= 3.0 - Two-Factor Authentication Bypass
Recently published
- CVE-2026-60134 — Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Security Decision
- CVE-2026-45055 — CubeCart: Pre-Authenticated Password Reset Link Poisoning via HTTP Host Header
- CVE-2024-9820 — WP 2FA with Telegram <= 3.0 - Two-Factor Authentication Bypass