> For the complete documentation index, see [llms.txt](https://csbygb.gitbook.io/pentips/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://csbygb.gitbook.io/pentips/web-pentesting/webvulns.md).

# Vunerabilities and attacks

- [Clickjacking](https://csbygb.gitbook.io/pentips/web-pentesting/webvulns/clickjacking.md)
- [CORS (Misconfigurations)](https://csbygb.gitbook.io/pentips/web-pentesting/webvulns/cors.md)
- [CSRF](https://csbygb.gitbook.io/pentips/web-pentesting/webvulns/csrf.md)
- [SSRF](https://csbygb.gitbook.io/pentips/web-pentesting/webvulns/ssrf.md)
- [Bypass captcha](https://csbygb.gitbook.io/pentips/web-pentesting/webvulns/captcha-bypass.md)
- [Template Injection (client and server side)](https://csbygb.gitbook.io/pentips/web-pentesting/webvulns/template-injection.md)
- [MFA bypass](https://csbygb.gitbook.io/pentips/web-pentesting/webvulns/mfa-bypass.md)
- [XXE](https://csbygb.gitbook.io/pentips/web-pentesting/webvulns/xxe.md)
