Invicti detected that CSP is implemented inside body tag.
This usage is not supported and will be ignored by the browsers.
Declare CSP in HTTP headers or with meta tags inside head element instead of body.
You can search and find all vulnerabilities
Strengthening enterprise application security: Invicti acquires Kondukto
Modern AppSec KPIs: Moving from scan counts to real risk reduction
Friends don’t let friends shift left: Shift smarter with DAST-first AppSec
Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding