| Insecure Default Initialization of Resource | |
| Improper Authentication | |
| Cross-site Request Forgery (CSRF) | |
| Missing Authorization | |
| Missing Authorization | |
| Authorization Bypass Through User-Controlled Key | |
| Missing Authorization | |
| Missing Authorization | |
| Authorization Bypass Through User-Controlled Key | |
| Incorrect Authorization | |
| Cross-site Request Forgery (CSRF) | |
| Server-side Request Forgery (SSRF) | |
| Missing Authorization | |
| Weak Password Recovery Mechanism for Forgotten Password | |
| Directory Traversal | |
| Incorrect Authorization | |
| Protection Mechanism Failure | |
| CSV Injection | |
| Missing Authorization | |
| Timing Attack | |
| Cross-site Scripting (XSS) | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Incomplete List of Disallowed Inputs | |
| Missing Authorization | |
| Improper Neutralization of Special Elements Used in a Template Engine | |
| XML External Entity (XXE) Injection | |
| Information Exposure | |
| Exposure of Sensitive Information to an Unauthorized Actor | |
| Eval Injection | |