| Open Redirect | |
| Brute Force | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) | |
| Open Redirect | |
| Business Logic Errors | |
| Authentication Bypass by Primary Weakness | |
| Access Control Bypass | |
| Allocation of Resources Without Limits or Throttling | |
| Cross-site Request Forgery (CSRF) | |
| Open Redirect | |
| Improper Privilege Management | |
| Missing Authentication for Critical Function | |
| Insufficient Session Expiration | |
| Business Logic Errors | |
| Insufficient Session Expiration | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Origin Validation Error | |
| Open Redirect | |
| Directory Traversal | |
| Weak Password Requirements | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Use of Cache Containing Sensitive Information | |
| Weak Password Requirements | |
| Improper Handling of Length Parameter Inconsistency | |
| Improper Handling of Length Parameter Inconsistency | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Cleanup on Thrown Exception | |
| Session Fixation | |
| Sensitive Cookie in HTTPS Session Without "Secure" Attribute | |
| Cross-site Request Forgery (CSRF) | |
| Cross-site Request Forgery (CSRF) | |
| Cross-site Request Forgery (CSRF) | |
| Cross-site Request Forgery (CSRF) | |
| Cross-site Request Forgery (CSRF) | |
| Weak Password Requirements | |
| Information Exposure | |
| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | |
| Improper Restriction of Rendered UI Layers or Frames (Clickjacking) | |