| Open Redirect | <7.17.29>=8.0.0 <8.17.8>=8.18.0 <8.18.3>=9.0.0 <9.0.3 |
| Incorrect Authorization | >=9.0.0 <9.0.6>=9.1.0 <9.1.3 |
| Cross-site Scripting (XSS) | >=7.0.0 <8.18.8>=8.19.0 <8.19.4>=9.0.0 <9.0.7>=9.1.0 <9.1.4 |
| Cross-site Scripting (XSS) | <8.18.8>=8.19.0 <8.19.5>=9.0.0 <9.0.8>=9.1.0 <9.1.5 |
| Insufficiently Protected Credentials | <8.1.0>=8.14.0 <8.18.8>=8.19.0 <8.19.5>=9.0.0 <9.0.8>=9.1.0 <9.1.5 |
| Cross-site Scripting (XSS) | >=7.0.0 <8.18.8>=8.19.0 <8.19.5>=9.0.0 <9.0.8>=9.1.0 <9.15 |
| Allocation of Resources Without Limits or Throttling | |
| Missing Authorization | |
| Prototype Pollution | >=8.3.0 <8.17.6>=8.18.0 <8.18.1>=9.0.0 <9.0.1 |
| Arbitrary File Upload | >=7.17.6 <7.17.24>=8.4.0 <8.12.0 |
| Arbitrary File Upload | >=7.17.0 <7.17.19>=8.0.0 <8.13.0 |
| Prototype Pollution | >=8.16.1 <8.16.4>=8.17.0 <8.17.2 |
| Prototype Pollution | |
| Allocation of Resources Without Limits or Throttling | |
| Information Exposure | |
| Server-side Request Forgery (SSRF) | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Deserialization of Untrusted Data | |
| Deserialization of Untrusted Data | |
| Prototype Pollution | >=7.7.0 <7.17.23>=8.0.0 <8.14.2 |
| Denial of Service (DoS) | >=7.0.0 <7.17.23>=8.0.0 <8.14.0 |
| Allocation of Resources Without Limits or Throttling | <7.17.22>=8.0.0-alpha1 <8.14.0 |
| URL Redirection to Untrusted Site ('Open Redirect') | <7.17.22>=8.0.0-alpha1 <8.14.0 |
| Uncontrolled Resource Consumption ('Resource Exhaustion') | |
| Improper Access Control | |
| Insertion of Sensitive Information into Log File | >=7.13.0 <7.17.16>=8.0.0 <8.11.2 |
| Information Exposure Through Log Files | |
| Use of Unmaintained Third Party Components | |
| Arbitrary Code Injection | |
| Directory Traversal | |
| Insertion of Sensitive Information into Log File | |
| Cleartext Transmission of Sensitive Information | |
| Denial of Service (DoS) | >=7.0.0 <7.17.9>=8.0.0 <8.6.1 |
| Arbitrary Code Injection | |
| Arbitrary Code Injection | |
| Improper Input Validation | |
| Open Redirect | |
| Prototype Pollution | >=6.7.0 <6.8.9>=7.0.0 <7.6.3 |
| Prototype Pollution | |
| Cross-site Scripting (XSS) | |
| Information Exposure | |
| Cross-site Request Forgery (CSRF) | |
| Cross-site Scripting (XSS) | >=4.1.0 <4.1.11>=4.5.0 <4.5.4 |
| Cross-site Scripting (XSS) | |
| Open Redirect | |
| Arbitrary Command Execution | |
| Cross-site Scripting (XSS) | >=5.1.1 <5.6.6>=6.0.0 <6.1.2 |
| Denial of Service (DoS) | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Open Redirect | >=5.1.1 <5.6.7>=6.0.0 <6.1.3 |
| Cross-site Scripting (XSS) | >=5.1.1 <5.6.7>=6.0.0 <6.1.3 |
| Cross-site Scripting (XSS) | |
| Open Redirect | |
| Open Redirect | |
| Denial of Service (DoS) | |
| Cross-site Scripting (XSS) | >=5.3.0 <5.3.3>=5.4.0 <5.4.1 |
| Information Exposure | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |