Total findings
10
Critical + high
5
Still open
4
Resolved
2
Findings by severity
- Critical2
- High3
- Medium2
- Low2
- Informational1
Remediation progress
20%
2 of 10 findings verified as resolved on retest.
Severity:
Status:
| ID | Finding | Severity | Area | Priority | Status |
|---|---|---|---|---|---|
| PS-001 | Login form accepts unlimited password attempts | Critical | /account/login | P1 | Open |
| PS-002 | Order details reachable by changing the order number | Critical | /account/orders/{id} | P1 | In progress |
| PS-003 | Stored script injection in product review field | High | /product/{slug} — review submission | P1 | Retest |
| PS-004 | Session cookie missing secure attributes | High | Global — session cookie | P2 | Resolved |
| PS-005 | Password reset tokens do not expire | High | /account/reset | P2 | Open |
| PS-006 | Verbose error page reveals framework and version | Medium | /checkout — 500 handler | P3 | In progress |
| PS-007 | File upload accepts oversized and unexpected types | Medium | /account/support — attachment | P3 | Open |
| PS-008 | Missing security headers | Low | Global — HTTP responses | P4 | Resolved |
| PS-009 | Directory listing enabled on asset folder | Low | /assets/uploads/ | P4 | Retest |
| PS-010 | Outdated JavaScript dependency in checkout bundle | Informational | Checkout bundle | P4 | Open |