| Improper Authentication | |
| Detection of Error Condition Without Action | |
| Always-Incorrect Control Flow Implementation | |
| Improper Authorization | |
| Always-Incorrect Control Flow Implementation | |
| Cross-site Scripting (XSS) | |
| Improper Input Validation | |
| Improper Authorization | |
| Improper Handling of Case Sensitivity | |
| Information Exposure | |
| Authentication Bypass | |
| Allocation of Resources Without Limits or Throttling | |
| Information Exposure | |
| CVE-2026-29146 | |
| CVE-2026-34500 | |
| CVE-2026-29145 | |
| Information Exposure Through Log Files | |
| Improper Encoding or Escaping of Output | |
| HTTP Request Smuggling | |
| Open Redirect | |
| Improper Input Validation | |
| Missing Encryption of Sensitive Data | |
| Improper Certificate Validation | |
| CVE-2026-29129 | |
| Improper Certificate Validation | |
| CVE-2026-24733 | |
| Improper Resource Shutdown or Release | |
| Improper Neutralization | |
| CVE-2026-24734 | |
| Directory Traversal | |