Sort Common Security Mistakes
Classify common frontend-adjacent security mistakes by likely risk type.
Sort each mistake into the OWASP-style risk area you would inspect first. Broken access control Injection or unsafe rendering Authentication/session risk Sensitive data exposure The admin page is protected only by hiding the nav link A user bio is rendered with direct HTML insertion Password reset reveals whether an email is registered A long-lived access token is stored where any injected script can read it The API accepts a userId from the browser to decide which invoices to show Search terms are inserted into the page with unescaped markup Login errors distinguish wrong password from unknown account publicly Debug output…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in