JavaScript / TypeScript

Pages117

Mass assignment

Mass assignment

Improper output encoding or escaping

Improper output encoding or escaping

Command injection

Command injection

Eval injection

Eval injection

Eval injection through dynamic require

Eval injection through dynamic require

Server-side eval injection

Server-side eval injection

Command injection

Command injection

Execution of hardcoded encoded data

Execution of hardcoded encoded data

Cross-site scripting in HTML template strings

Cross-site scripting in HTML template strings

Cross-site scripting through script-tag content

Cross-site scripting through script-tag content

Cross-site scripting through jQuery html()

Cross-site scripting through jQuery html()

Cross-site scripting through jQuery DOM methods

Cross-site scripting through jQuery DOM methods

Reflected cross-site scripting in Express

Reflected cross-site scripting in Express

Stored cross-site scripting in directory listings

Stored cross-site scripting in directory listings

CSRF middleware ordering

CSRF middleware ordering

Cleartext WebSocket transmission

Cleartext WebSocket transmission

Hardcoded HMAC key

Hardcoded HMAC key

Hardcoded JWT signing secret

Hardcoded JWT signing secret

Missing JWT signature verification

Missing JWT signature verification

Use of the JWT 'none' algorithm

Use of the JWT none algorithm

Weak password hashing with MD5

Weak password hashing with MD5

Disabled HTML escaping in Mustache

Disabled HTML escaping in Mustache

Use of the removed Buffer noAssert argument

Use of the removed Buffer noAssert argument

Out-of-range bit shift

Out-of-range bit shift

SQL injection in node-postgres queries

SQL injection in node-postgres queries

SQL injection in MySQL queries

SQL injection in MySQL queries

SQL injection in node-mssql queries

SQL injection in node-mssql queries

SQL injection in Knex queries

SQL injection in Knex queries

SQL injection

SQL injection

Regular expression denial of service (ReDoS)

Regular expression denial of service (ReDoS)

Denial of service through dynamic regular expressions (ReDoS)

Regular expression denial of service (ReDoS)

Prototype pollution

Prototype pollution

Prototype pollution

Prototype pollution

Remote property injection

Remote property injection

Path traversal

Path traversal

Path traversal

Path traversal

Path validation bypass through parameter type confusion

Path validation bypass through parameter type confusion

Use of the deprecated crypto.pseudoRandomBytes API

Use of the deprecated crypto.pseudoRandomBytes API

Overly permissive CORS regular expressions

Overly permissive CORS regular expressions with wildcards or unescaped dots

Cleartext HTTP endpoints in Axios

Cleartext HTTP endpoints in Axios requests

XSS from raw HTML in react-markdown

XSS from rendering raw HTML in react-markdown

XSS through React dangerouslySetInnerHTML

XSS through React dangerouslySetInnerHTML

Resource exhaustion with Ajv allErrors:true

Resource exhaustion from collecting all Ajv validation errors

Unvalidated dynamic method calls

Calling dynamically selected methods without validation

AngularJS SCE disabled

Disabling AngularJS Strict Contextual Escaping

Overly permissive AngularJS URL allow-lists

Overly permissive resource URL allow-lists in AngularJS $sce

Modulo bias in cryptographic random values

Modulo bias in cryptographic random values

Client-side request forgery

Client-side request forgery through unvalidated request URLs

Code injection through eval or dynamic template compilation

Code injection through evaluated input or dynamic template source

Wildcard target origin in postMessage

Data exposure through a wildcard postMessage target origin