| SQL Injection | |
| Information Exposure | |
| Cross-site Request Forgery (CSRF) | |
| Incorrect Authorization | |
| Authorization Bypass Through User-Controlled Key | |
| Server-side Request Forgery (SSRF) | |
| Information Exposure | |
| SQL Injection | |
| Improper Neutralization of Special Elements in Data Query Logic | |
| Information Exposure | |
| Server-side Request Forgery (SSRF) | |
| Incorrect Authorization | |
| SQL Injection | |
| Server-side Request Forgery (SSRF) | |
| Information Exposure | |
| Server-side Request Forgery (SSRF) | |
| SQL Injection | |
| Arbitrary File Upload | |
| Improper Neutralization of Special Elements in Data Query Logic | |
| Missing Authorization | |
| Cross-site Request Forgery (CSRF) | |
| Symlink Attack | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Missing Authorization | |
| Server-side Request Forgery (SSRF) | |
| Missing Authorization | |
| Server-side Request Forgery (SSRF) | |
| Incorrect Authorization | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Server-side Request Forgery (SSRF) | |
| Incorrect Authorization | |
| Arbitrary Code Injection | |
| Server-side Request Forgery (SSRF) | |
| Server-side Request Forgery (SSRF) | |
| Missing Authorization | |
| Server-side Request Forgery (SSRF) | |
| Command Injection | |
| Command Injection | |
| Directory Traversal | |
| Server-side Request Forgery (SSRF) | |
| Eval Injection | |