Threats Tagged 'cwe-1004'
View all threats tagged with 'cwe-1004'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-1004'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-35575: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ChurchCRM CRMCVE-2026-35575 0 ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s group-creation feature allows any user with group-creation privileges to inject malicious JavaScript that executes automatically when an administrator views the page. This enables attackers to steal the administrator’s session cookies, potentially leading to full administrative account takeover. This vulnerability is fixed in 6.5.3. Join the discussion | CVE Database V5 | 04/07/2026, 17:08:43 UTC Added: 04/07/2026, 18:46:19 UTC |
CVE-2026-39338: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ChurchCRM CRMCVE-2026-39338 0 ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerability exists in the search parameter accepted by the ChurchCRM dashboard. The application fails to sanitize or encode user-supplied input prior to rendering it within the browser's DOM. Although the application ultimately returns an HTTP 500 error due to the malformed API request caused by the payload, the browser's JavaScript engine parses and executes the injected <script> tags before the error response is returned — resulting in successful code execution regardless of the server-side error. This vulnerability is fixed in 7.1.0. Join the discussion | CVE Database V5 | 04/07/2026, 17:57:30 UTC Added: 04/07/2026, 18:16:12 UTC |
CVE-2026-0696: CWE-1004 Sensitive Cookie Without 'HttpOnly' Flag in ConnectWise PSACVE-2026-0696 0 In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values. Join the discussion | CVE Database V5 | 01/16/2026, 13:34:49 UTC Added: 01/16/2026, 13:51:36 UTC |
CVE-2026-22081: CWE-1004 - Sensitive Cookie Without HttpOnly Flag in Tenda 300Mbps Wireless Router F3 and N300 Easy Setup RouterCVE-2026-22081 0 This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker could exploit this vulnerability by capturing session cookies transmitted over an insecure HTTP connection. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and gain unau-thorized access to the targeted device. Join the discussion | CVE Database V5 | 01/09/2026, 11:16:21 UTC Added: 01/09/2026, 11:39:16 UTC |
CVE-2025-12031: CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag in Azure Access Technology BLU-IC2CVE-2025-12031 0 HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the javascript contextThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. Join the discussion | CVE Database V5 | 10/21/2025, 17:22:36 UTC Added: 10/21/2025, 17:34:52 UTC |
CVE-2025-42909: CWE-1004: Sensitive Cookie Without HttpOnly Flag in SAP_SE SAP Cloud Appliance Library AppliancesCVE-2025-42909 0 CVE-2025-42909 is a low-severity vulnerability in SAP Cloud Appliance Library Appliances, specifically affecting the TITANIUM_WEBAPP 4. 0 version. It involves a sensitive cookie lacking the HttpOnly flag due to an insecure default profile setting in S/4HANA appliances. An attacker with high privileges on one appliance could potentially access other appliances by exploiting this cookie vulnerability. The impact on confidentiality is low, and there is no impact on integrity or availability. Exploitation requires network access, high privileges, and no user interaction. No known exploits are currently reported in the wild. European organizations using SAP CAL appliances should review and harden their cookie security settings to mitigate risk. Countries with significant SAP enterprise deployments and critical infrastructure relying on SAP systems are more likely to be affected. Join the discussion | CVE Database V5 | 10/14/2025, 00:18:11 UTC Added: 10/14/2025, 00:50:02 UTC |
CVE-2025-53757: CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in Digisol XPON ONU Wi-Fi Router (DG-GR6821AC)CVE-2025-53757 0 This vulnerability exists in Digisol DG-GR6821AC Router due to misconfiguration of both Secure and HttpOnly flags on session cookies associated with the router web interface. A remote attacker could exploit this vulnerability by capturing the session cookies transmitted over an unsecure HTTP connection. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information from the targeted device. Join the discussion | CVE Database V5 | 07/16/2025, 11:25:05 UTC Added: 07/16/2025, 11:46:18 UTC |
CVE-2025-27453: CWE-1004 Sensitive Cookie Without 'HttpOnly' Flag in Endress+Hauser Endress+Hauser MEAC300-FNADE4CVE-2025-27453 0 The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such as JavaScript. Join the discussion | CVE Database V5 | 07/03/2025, 11:29:48 UTC Added: 07/03/2025, 11:39:31 UTC |
CVE-2025-49189: CWE-1004 Sensitive Cookie Without 'HttpOnly' Flag in SICK AG SICK Media ServerCVE-2025-49189 0 The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scripting attacks which target the stored cookies. Join the discussion | CVE Database V5 | 06/12/2025, 14:03:39 UTC Added: 06/12/2025, 14:23:30 UTC |
CVE-2025-47289: CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag in CE-PhoenixCart PhoenixCartCVE-2025-47289 0 CE Phoenix is a free, open-source eCommerce platform. A stored cross-site scripting (XSS) vulnerability was discovered in CE Phoenix versions 1.0.9.9 through 1.1.0.2 where an attacker can inject malicious JavaScript into the testimonial description field. Once submitted, if the shop owner (admin) approves the testimonial, the script executes in the context of any user visiting the testimonial page. Because the session cookies are not marked with the `HttpOnly` flag, they can be exfiltrated by the attacker — potentially leading to account takeover. Version 1.1.0.3 fixes the issue. Join the discussion | CVE Database V5 | 06/02/2025, 11:00:20 UTC Added: 06/02/2025, 12:10:50 UTC |
Showing 1 to 10 of 10 results