CSRF 12
- CSRF with broken Referer validation
- CSRF where Referer validation depends on header being present
- SameSite Lax bypass via cookie refresh
- SameSite Strict bypass via sibling domain
- SameSite Strict bypass via client-side redirect
- SameSite Lax bypass via method override
- CSRF where token is duplicated in cookie
- CSRF where token is tied to non-session cookie
- CSRF where token is not tied to user session
- CSRF where token validation depends on token being present
- CSRF where token validation depends on request method
- CSRF vulnerability with no defenses