Total findings

10

Critical + high

5

Still open

4

Resolved

2

Findings by severity

  • Critical
    2
  • High
    3
  • Medium
    2
  • Low
    2
  • Informational
    1

Remediation progress

20%

2 of 10 findings verified as resolved on retest.

Severity:
Status:
Demo findings, filterable by severity and status
IDFindingSeverityAreaPriorityStatus
PS-001Login form accepts unlimited password attemptsCritical/account/loginP1Open
PS-002Order details reachable by changing the order numberCritical/account/orders/{id}P1In progress
PS-003Stored script injection in product review fieldHigh/product/{slug} — review submissionP1Retest
PS-004Session cookie missing secure attributesHighGlobal — session cookieP2Resolved
PS-005Password reset tokens do not expireHigh/account/resetP2Open
PS-006Verbose error page reveals framework and versionMedium/checkout — 500 handlerP3In progress
PS-007File upload accepts oversized and unexpected typesMedium/account/support — attachmentP3Open
PS-008Missing security headersLowGlobal — HTTP responsesP4Resolved
PS-009Directory listing enabled on asset folderLow/assets/uploads/P4Retest
PS-010Outdated JavaScript dependency in checkout bundleInformationalCheckout bundleP4Open