Highest False Positives Last Month

These were the alerts most frequently flagged as false positives using Alert Filters last month.

Note that this does not necessarily mean they are false positives, it could mean that the people using ZAP are not interested in these specific vulnerabilities.

Position Alert Status Rule Type
1 Cookie without SameSite Attribute release Passive
2 Information Disclosure - Suspicious Comments release Passive
3 Session ID in URL Rewrite release Passive
4 SQL Injection release Active
5 Cross-Domain Misconfiguration release Passive
6 X-Content-Type-Options Header Missing release Passive
7 Loosely Scoped Cookie release Passive
8 Source Code Disclosure - PHP beta Passive
9 Re-examine Cache-control Directives release Passive
10 Retrieved from Cache release Passive
11 Content Security Policy (CSP) Header Not Set release Passive
12 Strict-Transport-Security Header release Passive
13 Session Management Response Identified beta Passive
14 Cross-Domain JavaScript Source File Inclusion release Passive
15 CSP release Passive
16 HTTP Server Response Header release Passive
17 Modern Web Application release Passive
18 Timestamp Disclosure - Unix release Passive
19 User Controllable HTML Element Attribute (Potential XSS) release Passive
20 Backup File Disclosure beta Active