Vulnerability Categories

The vulnerabilities found in the Shop are categorized into several different classes. Most of them cover different risk or vulnerability types from well-known lists or documents, such as OWASP Top 10 or MITRE's Common Weakness Enumeration. The following table presents a mapping of the Shop's categories to OWASP and CWE (without claiming to be complete).

Category Mappings

Category

OWASP

CWE

Injection

Broken Authentication

Forgotten Content

Roll your own Security

Sensitive Data Exposure

XML External Entities (XXE)

Improper Input Validation

Broken Access Control

Security Misconfiguration

Cross Site Scripting (XSS)

Insecure Deserialization

Vulnerable Components

Security through Obscurity

Last updated