| Cross-site Scripting (XSS) | |
| Cleartext Storage of Sensitive Information | |
| Improper Privilege Management | |
| Expression Language Injection | |
| OS Command Injection | |
| Time-of-check Time-of-use (TOCTOU) | |
| Cross-site Scripting (XSS) | |
| Authorization Bypass Through User-Controlled Key | |
| Incorrect Authorization | |
| Server-Side Request Forgery (SSRF) | |
| Incorrect Authorization | |
| Information Exposure Through Log Files | |
| Incorrect Authorization | |
| Missing Authentication for Critical Function | |
| Authorization Bypass Through User-Controlled Key | |
| Allocation of Resources Without Limits or Throttling | |
| Information Exposure | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Protection Mechanism Failure | |
| Improper Authentication | |
| Incorrect Authorization | |
| Authorization Bypass Through User-Controlled Key | |
| SQL Injection | |
| Incorrect Authorization | |
| Incorrect Authorization | |
| Incomplete Blacklist | |
| Incorrect Authorization | |
| Information Exposure | |
| Directory Traversal | |
| Information Exposure | |
| Improper Input Validation | |
| Cross-site Scripting (XSS) | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Cross-site Scripting (XSS) | |
| Authentication Bypass | |
| Exposure of Data Element to Wrong Session | |
| Cross-site Scripting (XSS) | |
| Missing Authentication for Critical Function | |
| Improper Handling of Highly Compressed Data (Data Amplification) | |
| SQL Injection | |
| SQL Injection | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Arbitrary Argument Injection | |
| SQL Injection | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Authorization Bypass Through User-Controlled Key | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |