| Authentication Bypass by Primary Weakness | |
| Improper Handling of Case Sensitivity | |
| Allocation of Resources Without Limits or Throttling | |
| Insecure Default Initialization of Resource | |
| Reliance on Untrusted Inputs in a Security Decision | |
| Incorrect Behavior Order: Authorization Before Parsing and Canonicalization | |
| Insufficient Logging | |
| Detection of Error Condition Without Action | |
| Authentication Bypass | |
| Cross-site Scripting (XSS) | |
| Improperly Implemented Security Check for Standard | |
| Incorrect Behavior Order: Authorization Before Parsing and Canonicalization | |
| Information Exposure | |
| Information Exposure | |
| Incorrect Implementation of Authentication Algorithm | |
| Improper Input Validation | |
| Improper Validation of Unsafe Equivalence in Input | |
| Improper Resource Shutdown or Release | |
| Improper Neutralization | |
| Improper Certificate Validation | |
| Directory Traversal | |
| Session Fixation | |