- A1 - Injection
- A2 - Broken Authentication and Session Management
- A3 - Cross-site Scripting (XSS)
- A4 - Insecure Direct Object Reference
- A5 - Security Misconfiguration
- not implemented
- A6 - Sensitive Data Exposure
- A7 - Missing Function Level Access Control
- A8 - Cross Site Request Forgery
- not implemented
- A9 - Using Components with Known Vulnerabilities
- not implemented
- A10 - Unvalidated Redirects and Forwards
- not implemented