| Cross-site Request Forgery (CSRF) | |
| Directory Traversal | |
| Cross-site Scripting (XSS) | |
| Cross-site Request Forgery (CSRF) | |
| Guessable CAPTCHA | |
| Server-side Request Forgery (SSRF) | |
| Permissive Cross-domain Policy with Untrusted Domains | |
| Origin Validation Error | |
| Cross-site Request Forgery (CSRF) | |
| Directory Traversal | |
| Active Debug Code | |
| Cross-site Request Forgery (CSRF) | |
| Arbitrary Code Injection | |
| Authorization Bypass Through User-Controlled Key | |
| Directory Traversal | |
| Server-side Request Forgery (SSRF) | |
| Cross-site Scripting (XSS) | |
| Server-side Request Forgery (SSRF) | |
| Insufficient Verification of Data Authenticity | |
| Missing Authorization | |
| Missing Authentication for Critical Function | |
| Information Exposure | |
| Information Exposure | |
| Missing Authorization | |
| Cross-site Request Forgery (CSRF) | |
| Cross-site Scripting (XSS) | |
| Server-side Request Forgery (SSRF) | |
| Access Control Bypass | |
| Improper Authorization | |
| Cross-site Scripting (XSS) | |
| Missing Authentication for Critical Function | |
| Missing Authentication for Critical Function | |
| Missing Authorization | |
| Cross-site Request Forgery (CSRF) | |
| Cross-site Scripting (XSS) | |
| Cross-site Request Forgery (CSRF) | |
| Missing Authorization | |
| Cross-site Scripting (XSS) | |
| Cross-site Request Forgery (CSRF) | |
| Cross-site Scripting (XSS) | |
| Missing Authorization | |
| Incorrect Authorization | |
| Race Condition | |
| Insufficient Session Expiration | |
| Missing Authorization | |
| Missing Authorization | |
| Missing Authorization | |
| Cleartext Storage of Sensitive Information | |
| Missing Authorization | |
| SQL Injection | |
| Missing Authorization | |
| Brute Force | |
| Server-side Request Forgery (SSRF) | |
| Authorization Bypass Through User-Controlled Key | |
| SQL Injection | |
| Arbitrary File Upload | |
| SQL Injection | |
| Missing Authentication for Critical Function | |
| Server-side Request Forgery (SSRF) | |
| Cross-site Scripting (XSS) | |
| Server-side Request Forgery (SSRF) | |
| Directory Traversal | |
| Missing Authorization | |
| Use of Less Trusted Source | |
| Information Exposure | |
| Arbitrary File Upload | |
| Cross-site Request Forgery (CSRF) | |
| Command Injection | |
| Incorrect Authorization | |
| SQL Injection | |
| Access Control Bypass | |
| PHP Remote File Inclusion | |
| Use of a Broken or Risky Cryptographic Algorithm | |
| Cross-site Request Forgery (CSRF) | |
| Arbitrary Code Injection | |
| Server-side Request Forgery (SSRF) | |
| Server-side Request Forgery (SSRF) | |
| Inadequate Encryption Strength | |
| Command Injection | |
| Directory Traversal | |
| Session Fixation | |
| SQL Injection | |
| Missing Authorization | |
| Allocation of Resources Without Limits or Throttling | |
| Cross-site Scripting (XSS) | |
| Server-side Request Forgery (SSRF) | |
| External Control of File Name or Path | |
| SQL Injection | |
| Authorization Bypass Through User-Controlled Key | |
| Open Redirect | |
| Cross-site Scripting (XSS) | |
| Server-side Request Forgery (SSRF) | |
| Directory Traversal | |
| Directory Traversal | |
| Missing Authentication for Critical Function | |
| Directory Traversal | |
| Cross-site Scripting (XSS) | |
| Command Injection | |
| Server-side Request Forgery (SSRF) | |
| Cross-site Scripting (XSS) | |
| Permissive Cross-domain Policy with Untrusted Domains | |
| Missing Authentication for Critical Function | |
| Server-side Request Forgery (SSRF) | |
| Information Exposure | |
| Missing Authorization | |
| SQL Injection | |
| Arbitrary File Upload | |
| Server-side Request Forgery (SSRF) | |
| Cross-site Scripting (XSS) | |
| Improper Control of Generation of Code ('Code Injection') | |
| Improper Authentication | |
| Insufficient Entropy | |
| Improper Restriction of Excessive Authentication Attempts | |
| Arbitrary Command Injection | |
| Cross-site Scripting (XSS) | |
| Remote Code Execution (RCE) | |
| Cross-site Scripting (XSS) | |
| Command Injection | |
| Improper Privilege Management | |
| Open Redirect | |
| Cross-site Scripting (XSS) | |