Weak Content-Security-Policy
infoYou have a Content-Security-Policy, which is great — but it contains a wildcard source or allows 'unsafe-inline'/'unsafe-eval' in script-src. Those let injected scripts execute, which is most of what a CSP is meant to stop.