web2-vuln-classes

Catalog 18 web2 vulnerability classes with detection patterns and testing checklists.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/venkatas/obsidian --skill web2-vuln-classes
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: web2-vuln-classes
Source: https://github.com/venkatas/obsidian/tree/main/skills/web2-vuln-classes
Command: npx skills add https://github.com/venkatas/obsidian --skill web2-vuln-classes

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This reference consolidates 18 essential web2 vulnerability classes, mapping root causes, detection patterns, bypass techniques, and real-world examples to accelerate security research and assessment.

Core Features & Use Cases

  • Comprehensive coverage of common web2 bugs (IDOR, auth bypass, XSS, SSRF, SQLi, SSTI, OAuth/OIDC, file upload, GraphQL, and more) with practical patterns and testing guidance.
  • Structured guidance for detection, reproduction, and remediation, including risk levels and impact chains for prioritized defense.
  • Use Case: A red team analyst probes a target web app to identify likely vulnerability classes, verify findings with repeatable tests, and prepare a mitigation-focused report.

Quick Start

Identify a target vulnerability class from the list and review its root causes and detection patterns to guide your assessment.

Frequently Asked Questions about web2-vuln-classes

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are the most common web2 vulnerability classes I should test for during a security assessment?

Common web2 vulnerability classes include IDOR, XSS, SSRF, SQLi, SSTI, OAuth/OIDC, auth bypass, and file upload flaws. This reference catalogs 18 distinct vulnerability classes, mapping root causes and detection patterns to guide security research and testing.

How do I identify and detect web2 vulnerabilities like IDOR and SSRF during recon?

To detect web2 vulnerabilities like IDOR and SSRF, review their specific root causes and detection patterns. This reference provides structured detection guidance and testing checklists for 18 classes to help identify and verify likely vulnerabilities in target applications.

What bypass techniques exist for common web2 security vulnerabilities?

Bypass techniques for web2 vulnerabilities vary by class and target implementation. This reference catalogs bypass techniques alongside real-world examples for 18 vulnerability classes, accelerating security research by providing practical patterns for verification and testing.

Does this web2 vulnerability reference cover modern API and authentication flaws like GraphQL and OAuth?

Yes, this web2 vulnerability reference covers modern API and authentication flaws including GraphQL and OAuth/OIDC. It spans 18 vulnerability classes total, providing root causes, detection patterns, and remediation guidance for both traditional and contemporary web2 attack surfaces.

How do I plan remediation for detected web2 vulnerabilities?

Plan remediation for detected web2 vulnerabilities by mapping root causes and assessing impact. This reference provides structured guidance for prioritized defense, including risk levels and impact chains across 18 vulnerability classes to focus mitigation efforts effectively.

Can I use this for red team testing and reproduction of web2 bugs?

Yes, you can use this for red team testing and reproduction of web2 bugs. It provides repeatable testing checklists and real-world examples across 18 vulnerability classes, allowing analysts to probe target apps, verify findings, and prepare mitigation-focused reports.