Other findings

  • server-side request forgery (medium-risk incidence most common)
  • cross-site scripting (medium-risk incidence most common)
  • broken authentication (medium-risk incidence most common)
  • security misconfigurations (low-risk incidence most common)
  • insufficient protection from brute-force attacks (low-risk incidence most common)
  • using code components with known vulnerabilities (low- and medium- risk incidence most common)