VAPT errors and how to fix them?

i am in 7-8 month older version of cockpit, but ondoing Vulnerability Assessment and Penetration Testing by my client, they found

  1. PII Disclosure

  2. stored xss and xss through file upload ,

  3. CSRF Token Reuse,

  4. Authentication Bypass via Response Manipulation

  5. Session Hijacking,

    are any of these these resolved in latest version? if not guide to fix them

Note it was a plain installation , with little to no customization.

which version are you on?

It would also make sense the share the findings privately or do an assessment in general against a newer version

okay i am sending you the reports today