Invicti detected that you used default-src in CSP directive. It is important to know that default-src cannot be used as a fallback for the functions below:
base-uri
form-action
frame-ancestors
plugin-types
report-uri
sandbox
You can search and find all vulnerabilities