| Interpretation Conflict | |
| User Interface (UI) Misrepresentation of Critical Information | |
| Incomplete Blacklist | |
| Encoding Error | |
| Improper Verification of Cryptographic Signature | |
| Incorrect Authorization | |
| Cross-site Scripting (XSS) | |
| Authentication Bypass | |
| Incorrect Authorization | |
| CVE-2026-45753 | |
| Cross-site Scripting (XSS) | |
| Improper Authentication | |
| Missing Authentication for Critical Function | |
| Arbitrary Argument Injection | |
| CRLF Injection | |
| XML External Entity (XXE) Injection | |
| Insufficient Verification of Data Authenticity | |
| Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | |
| CRLF Injection | |
| User Interface (UI) Misrepresentation of Critical Information | |
| Incomplete Blacklist | |
| Uncontrolled Recursion | |
| CVE-2026-46626 | |
| SQL Injection | |
| Missing Authentication for Critical Function | |
| Incorrect Regular Expression | |
| Resource Exhaustion | |
| Inefficient Regular Expression Complexity | |
| Authentication Bypass | |
| Deserialization of Untrusted Data | |
| Use of Non-Canonical URL Paths for Authorization Decisions | |
| CVE-2024-36611 | |
| Improper Authentication | |
| CVE-2024-50341 | |
| Improper Input Validation | |
| Open Redirect | |
| Arbitrary Code Injection | |
| Information Exposure | |
| CVE-2023-46733 | |
| Cross-site Scripting (XSS) | |
| CVE-2022-24894 | |
| Insufficient Session Expiration | |
| Improper Neutralization of Formula Elements in a CSV File | |
| Information Exposure | |
| Improper Cross-boundary Removal of Sensitive Data | |
| Information Exposure | |
| Incorrect Authorization | |
| Improper Input Validation | |
| Information Exposure | |
| Improper Encoding or Escaping of Output | |
| Arbitrary Code Injection | |
| Improper Input Validation | |
| Information Exposure | |
| Improper Authentication | |
| Cross-site Scripting (XSS) | |
| Deserialization of Untrusted Data | |
| SQL Injection | |
| Cross-site Scripting (XSS) | |
| Open Redirect | |
| Unrestricted Upload of File with Dangerous Type | |
| CVE-2018-14773 | |
| Improper Input Validation | |
| Directory Traversal | |
| CVE-2017-16653 | |
| Improper Input Validation | |
| Cross-site Scripting (XSS) | |
| CVE-2015-2309 | |
| Cross-site Scripting (XSS) | |
| Improper Authentication | |
| Open Redirect | |
| Insufficient Session Expiration | |
| Open Redirect | |
| Session Fixation | |
| Cross-site Request Forgery (CSRF) | |
| Improper Authentication | |
| Cryptographic Issues | |
| Resource Management Errors | |
| CVE-2015-8125 | |
| CVE-2015-8124 | |
| Arbitrary Code Injection | |
| Improper Access Control | |
| CVE-2008-7220 | |
| CVE-2007-2383 | |