Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Api Bfla Api Bola Api Broken Auth Api Broken Object Prop Auth Api Dos Api Improper Inventory Management Api Misconfiguration Api Ssrf Arbitrary File Creation Arbitrary File Read Authentication Bypass BOLA Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial Of Service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilities LLM Ldap Injection Llm Excessive Agency Llm Insecure Output Handling Llm Prompt Injection Llm Prompt Leakage Llm Sensitive Information Disclosure Malware Missing Update Privilege Escalation SSRF Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Vulnerability Name CVE CWE CWE Severity (Possible) Cross site scripting CWE-79 CWE-79 Informational .htaccess File Detected CWE-529 CWE-529 Informational Access-Control-Allow-Origin header with wildcard (*) value CWE-942 CWE-942 Informational An Unsafe Content Security Policy (CSP) Directive in Use CWE-942 CWE-942 Informational Apple's App-Site Association (AASA) file CWE-200 CWE-200 Informational Content-Security-Policy-Report-Only Cannot Be Declared Between META Tags CWE-358 CWE-358 Informational Content-Security-Policy-Report-Only Cannot Be Declared Without report-uri Directive CWE-358 CWE-358 Informational Content Security Policy (CSP) Contains Out of Scope report-uri Domain CWE-358 CWE-358 Informational Content Security Policy (CSP) Keywords Not Used Within Single Quotes CWE-942 CWE-942 Informational Content Security Policy (CSP) Nonce Value Not Used Within Single Quotes CWE-358 CWE-358 Informational Content Security Policy (CSP) Nonce Without Matching Script Block CWE-358 CWE-358 Informational Content Security Policy (CSP) Not Implemented CWE-1021 CWE-1021 Informational Content Security Policy (CSP) report-uri Uses HTTP CWE-319 CWE-319 Informational Content Security Policy Misconfiguration CWE-942 CWE-358 CWE-942 CWE-358 Informational Cookies with Secure flag set over insecure connection CWE-614 CWE-614 Informational Cross-Origin-Embedder-Policy (COEP) needs improvements CWE-203 CWE-359 CWE-203 CWE-359 Informational Cross-Origin-Embedder-Policy (COEP) Not Implemented CWE-203 CWE-359 CWE-203 CWE-359 Informational Cross-Origin Opener Policy (COOP) Needs Improvements CWE-942 CWE-1022 CWE-942 CWE-1022 Informational Cross-Origin Opener Policy (COOP) Not Implemented CWE-942 CWE-1022 CWE-942 CWE-1022 Informational Cross-Origin Opener Policy (COOP) Syntax Error CWE-942 CWE-1022 CWE-942 CWE-1022 Informational Cross site scripting (requiring unencoded quote) CWE-79 CWE-79 Informational Cross site scripting (requiring unencoded tag delimiter) CWE-79 CWE-79 Informational data: Used in a Content Security Policy (CSP) Directive CWE-942 CWE-942 Informational default-src Used in Content Security Policy (CSP) CWE-942 CWE-942 Informational Deprecated Header Instruction Used to Implement Content Security Policy (CSP) CWE-358 CWE-358 Informational Error page web server version disclosure CWE-200 CWE-200 Informational Express express-session weak secret key CWE-693 CWE-693 Informational File Upload Functionality Detected Informational Generic Email Address Disclosure CWE-200 CWE-200 Informational HTML Injection (requiring unencoded tag delimiter) CWE-80 CWE-80 Informational HTTP Strict Transport Security (HSTS) Errors and Warnings CWE-1428 CWE-319 CWE-1428 CWE-319 Informational Incorrect Content Security Policy (CSP) Implementation CWE-942 CWE-942 Informational Insecure Protocol Detected in Content Security Policy (CSP) CWE-942 CWE-942 Informational Insecure Referrer Policy CWE-200 CWE-200 Informational Invalid Content Security Policy (CSP) Directive Identified in meta Elements CWE-358 CWE-358 Informational Javascript Source map detected CWE-200 CWE-200 Informational JVM version leakage CWE-200 CWE-200 Informational LLM Model Detected CWE-200 CWE-200 Informational LLM Response Pattern Detected CWE-200 CWE-200 Informational Magento 2.0-2.3 End of life CWE-1104 CWE-1104 Informational Microsoft Frontpage configuration information CWE-200 CWE-200 Informational Missing object-src in CSP Declaration CWE-942 CWE-942 Informational Multiple Content Security Policy (CSP) Implementation Detected CWE-358 CWE-358 Informational Nonce Usage Detected in Content Security Policy (CSP) Directive CWE-358 CWE-358 Informational No Script Block Detected with the Hash Value Declared in Content Security Policy (CSP) CWE-942 CWE-942 Informational Oracle JRE CVE-2012-0547 Vulnerability (CVE-2012-0547) CVE-2012-0547 Informational Oracle JRE Other Vulnerability (CVE-2012-5085) CVE-2012-5085 Informational Outdated JavaScript libraries CWE-1395 CWE-1395 Informational Permissions-Policy header not implemented CWE-1021 CWE-1021 Informational Potential Sensitive Data Disclosure Informational Retired hash function in SAML Response CWE-327 CWE-327 Informational Reverse Proxy Detected Informational Scheme URI Detected in Content Security Policy (CSP) Directive CWE-942 CWE-942 Informational Static Nonce Identified in Content Security Policy (CSP) CWE-334 CWE-334 Informational Subresource Integrity (SRI) Not Implemented CWE-830 CWE-830 Informational TLS/SSL (EC)DHE Key Reuse CWE-327 CWE-327 Informational Typo3 Admin publicly accessible CWE-200 CWE-200 Informational Unsupported Hash Detected in Content Security Policy (CSP) CWE-327 CWE-327 Informational Weak Nonce Detected in Content Security Policy (CSP) Declaration CWE-942 CWE-330 CWE-942 CWE-330 Informational Web Application Firewall Detected Informational WebDAV Enabled CWE-749 CWE-749 Informational Web server default welcome page CWE-200 CWE-200 Informational Wildcard Detected in Domain Portion of Content Security Policy (CSP) Directive CWE-942 CWE-942 Informational Wildcard Detected in Port Portion of Content Security Policy (CSP) Directive CWE-942 CWE-942 Informational Wildcard Detected in Scheme Portion of Content Security Policy (CSP) Directive CWE-942 CWE-942 Informational WordPress readme.html file CWE-200 CWE-200 Informational WordPress user registration enabled Informational X-Content-Type-Options (XCTO) Not Implemented Informational [Possible] Internal Path Disclosure (*nix) CWE-200 CWE-200 Informational [Possible] Internal Path Disclosure (Windows) CWE-200 CWE-200 Informational [Possible] WS_FTP Log File Detected CWE-538 CWE-538 Informational