| Information Exposure Through Log Files | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Information Exposure | |
| SQL Injection | |
| Information Exposure | |
| Deserialization of Untrusted Data | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| XML External Entity (XXE) Injection | |
| Information Exposure | |
| Use of a Broken or Risky Cryptographic Algorithm | |
| Improper Access Control | |
| Missing Required Cryptographic Step | |
| Missing Required Cryptographic Step | |
| Information Exposure | |
| Covert Timing Channel | |
| Incorrect Calculation | |
| Missing Required Cryptographic Step | |
| Missing Required Cryptographic Step | |
| Missing Required Cryptographic Step | |
| Directory Traversal | |
| Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) | |
| Improper Certificate Validation | |
| Cross-site Scripting (XSS) | |
| SQL Injection | |
| Cleartext Storage of Sensitive Information | |
| Insufficient Verification of Data Authenticity | |
| Deserialization of Untrusted Data | |
| Improper Input Validation | |
| Insecure Temporary File | |
| Insufficiently Protected Credentials | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Improper Authorization | |
| Improper Authorization | |
| Cross-site Scripting (XSS) | |
| Information Exposure Through Log Files | |
| Information Exposure | |
| Improper Access Control | |
| Use of Insufficiently Random Values | |
| Incorrect Permission Assignment for Critical Resource | |
| Improper Input Validation | |
| Improper Access Control | |
| Cross-site Scripting (XSS) | |
| Improper Input Validation | |
| Incorrect Permission Assignment for Critical Resource | |
| Race Condition | |
| Insecure Temporary File | |
| Incorrect Permission Assignment for Critical Resource | |
| Cross-site Scripting (XSS) | |
| Cleartext Transmission of Sensitive Information | |
| Improper Access Control | |
| Information Exposure | |
| Improper Input Validation | |
| Improper Input Validation | |
| Cross-site Scripting (XSS) | |
| Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | |
| Information Exposure | |
| Incomplete Blacklist | |
| Integer Overflow or Wraparound | |
| Improper Input Validation | |
| Out-of-Bounds | |
| CVE-2016-6346 | |