These were the alerts most frequently flagged as false positives using Alert Filters last month.
Note that this does not necessarily mean they are false positives, it could mean that the people using ZAP are not interested in these specific vulnerabilities.
| Position | Alert | Status | Rule Type |
|---|---|---|---|
| 1 | Cookie without SameSite Attribute | release | Passive |
| 2 | SQL Injection | release | Active |
| 3 | Information Disclosure - Suspicious Comments | release | Passive |
| 4 | Session ID in URL Rewrite | release | Passive |
| 5 | Cross-Domain Misconfiguration | release | Passive |
| 6 | X-Content-Type-Options Header Missing | release | Passive |
| 7 | Source Code Disclosure - PHP | beta | Passive |
| 8 | Re-examine Cache-control Directives | release | Passive |
| 9 | Loosely Scoped Cookie | release | Passive |
| 10 | Retrieved from Cache | release | Passive |
| 11 | Content Security Policy (CSP) Header Not Set | release | Passive |
| 12 | Strict-Transport-Security Header | release | Passive |
| 13 | Cross-Domain JavaScript Source File Inclusion | release | Passive |
| 14 | CSP | release | Passive |
| 15 | Session Management Response Identified | beta | Passive |
| 16 | HTTP Server Response Header | release | Passive |
| 17 | Cookie No HttpOnly Flag | release | Passive |
| 18 | Modern Web Application | release | Passive |
| 19 | Timestamp Disclosure - Unix | release | Passive |
| 20 | Anti-clickjacking Header | release | Passive |