| Arbitrary Code Injection | |
| Resource Management Errors | |
| Cross-site Scripting (XSS) | |
| Information Exposure | |
| XML External Entity (XXE) Injection | |
| Improper Verification of Cryptographic Signature | |
| Cross-site Scripting (XSS) | |
| Inadequate Encryption Strength | |
| Improper Input Validation | |
| Improper Verification of Cryptographic Signature | |
| Open Redirect | |
| Insufficient Session Expiration | |
| Information Exposure | |
| Improper Handling of Exceptional Conditions | |
| Improper Verification of Cryptographic Signature | |
| Information Exposure Through Log Files | |
| Improper Verification of Cryptographic Signature | |
| CVE-2018-6521 | |
| Information Exposure | |
| Improper Input Validation | |
| Cross-site Scripting (XSS) | |
| XML External Entity (XXE) Injection | |
| Cross-site Scripting (XSS) | |
| Session Fixation | |
| Improper Input Validation | |
| Session Fixation | |
| Improper Verification of Cryptographic Signature | |