Allowlist Bypass
|
Unvalidated Redirects |
700 |
|
Outdated Allowlist
|
Unvalidated Redirects |
100 |
|
Vulnerable Library
|
Vulnerable Components |
700 |
|
Forged Feedback
|
Broken Access Control |
450 |
|
Legacy Typosquatting
|
Vulnerable Components |
700 |
|
Email Leak
|
Sensitive Data Exposure |
1000 |
|
Premium Paywall
|
Cryptographic Issues |
1350 |
|
Deluxe Fraud
|
Improper Input Validation |
450 |
|
Login Jim
|
Injection |
450 |
|
Retrieve Blueprint
|
Sensitive Data Exposure |
1000 |
|
Access Log
|
Sensitive Data Exposure |
700 |
|
Supply Chain Attack
|
Vulnerable Components |
1000 |
|
Login Support Team
|
Security Misconfiguration |
1350 |
|
Password Strength
|
Broken Authentication |
250 |
|
Bully Chatbot
|
Miscellaneous |
100 |
|
Reflected XSS
|
XSS |
250 |
|
Bjoern's Favorite Pet
|
Broken Authentication |
450 |
|
View Basket
|
Broken Access Control |
250 |
|
Bonus Payload
|
XSS |
100 |
|
DOM XSS
|
XSS |
100 |
|
Exposed Metrics
|
Sensitive Data Exposure |
100 |
|
Forgotten Developer Backup
|
Sensitive Data Exposure |
700 |
|
Admin Section
|
Broken Access Control |
250 |
|
Blockchain Hype
|
Security through Obscurity |
1000 |
|
Easter Egg
|
Broken Access Control |
700 |
|
Error Handling
|
Security Misconfiguration |
100 |
|
Forgotten Sales Backup
|
Sensitive Data Exposure |
700 |
|
Login Admin
|
Injection |
250 |
|
Misplaced Signature File
|
Sensitive Data Exposure |
700 |
|
Nested Easter Egg
|
Cryptographic Issues |
700 |
|
Privacy Policy
|
Miscellaneous |
100 |
|
Security Policy
|
Miscellaneous |
250 |
|
Zero Stars
|
Improper Input Validation |
100 |
|
Missing Encoding
|
Improper Input Validation |
100 |
|
Poison Null Byte
|
Improper Input Validation |
700 |
|
Mass Dispel
|
Miscellaneous |
100 |
|
Score Board
|
Miscellaneous |
100 |
|
Confidential Document
|
Sensitive Data Exposure |
100 |
|