jQuery 3.3.1 (CVE-2020-11022, CVSS 6.1) - Express.js 4.17.1 (CVE-2022-24999, CVSS 7.5) - GraphQL introspection enabled (no CVE, information disclosure) - Missing Content-Security-Policy header - WordPress 5.8 at /blog/ with 3 vulnerable plugins