I solved Very High Code Injection (AdditionalTables.php - class.webResource.php - soap.php - soap2.php) and some XSS