| Cross-site Scripting (XSS) | |
| Directory Traversal | |
| Link Following | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Cross-site Scripting (XSS) | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| NULL Pointer Dereference | |
| Inefficient Regular Expression Complexity | |
| Allocation of Resources Without Limits or Throttling | |
| Reachable Assertion | |
| Reliance on Untrusted Inputs in a Security Decision | |
| Expression Language Injection | |
| CVE-2026-69198 | |
| CVE-2026-69192 | |
| Directory Traversal | |
| Uncontrolled Recursion | |
| Improper Validation of Unsafe Equivalence in Input | |
| Allocation of Resources Without Limits or Throttling | |
| Directory Traversal | |
| Server-Side Request Forgery (SSRF) | |
| Open Redirect | |
| Cross-site Scripting (XSS) | |
| Deserialization of Untrusted Data | |
| Open Redirect | |
| Cross-site Scripting (XSS) | |
| Allocation of Resources Without Limits or Throttling | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Unchecked Input for Loop Condition | |
| Access of Resource Using Incompatible Type ('Type Confusion') | |
| Allocation of Resources Without Limits or Throttling | |
| Misinterpretation of Input | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Improper Null Termination | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Verification of Source of a Communication Channel | |
| Origin Validation Error | |
| Cross-site Scripting (XSS) | |
| Inefficient Regular Expression Complexity | |
| CRLF Injection | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Incorrect Behavior Order: Authorization Before Parsing and Canonicalization | |
| Inefficient Regular Expression Complexity | |
| Cross-site Scripting (XSS) | |
| Excessive Platform Resource Consumption within a Loop | |
| Improper Neutralization of Equivalent Special Elements | |
| Inappropriate Encoding for Output Context | |
| Cross-site Request Forgery (CSRF) | |
| Excessive Platform Resource Consumption within a Loop | |
| Cross-site Scripting (XSS) | |
| Access of Uninitialized Pointer | |
| Cross-site Scripting (XSS) | |
| Open Redirect | |
| CRLF Injection | |
| Improper Validation of Syntactic Correctness of Input | |
| Improper Verification of Source of a Communication Channel | |
| Improper Validation of Syntactic Correctness of Input | |
| Uncontrolled Recursion | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Allocation of Resources Without Limits or Throttling | |
| Origin Validation Error | |
| Information Exposure | |
| Information Exposure | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| OS Command Injection | |
| XML Injection | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Out-of-bounds Write | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Server-Side Request Forgery (SSRF) | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Insufficient Granularity of Access Control | |
| Comparison Using Wrong Factors | |
| CRLF Injection | |
| Cross-site Scripting (XSS) | |
| Improper Cross-boundary Removal of Sensitive Data | |
| Out-of-bounds Write | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Arbitrary Code Injection | |
| Inefficient Regular Expression Complexity | |
| Unchecked Input for Loop Condition | |
| Expression Language Injection | |
| Inefficient Regular Expression Complexity | |
| Unchecked Input for Loop Condition | |
| Improper Validation of Specified Type of Input | |
| Inefficient Regular Expression Complexity | |
| Deserialization of Untrusted Data | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Access of Resource Using Incompatible Type ('Type Confusion') | |
| Cross-site Scripting (XSS) | |
| Open Redirect | |
| Cross-site Scripting (XSS) | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Use of Incorrectly-Resolved Name or Reference | |