SQL injection in OrderRepository.findByCustomer
Agent recommends
~2h
Findings from all sources · agent triaged each one · pick what becomes sprint work
SEC-1753 is missing CWE classification — agent will skip until classified.
admin-portal. Output-encoding all 14 fields is symptom-only and recurs on every edit. Recommend converting to engineering epic: migrate to Thymeleaf.
SafeFileResolver utility instead of patching each handler.