What if we add a new field that describes who is affected by vulnerability?
{
"id": 45,
"title": "SQL Injection",
"affect": "server"
or
{
"id": 70,
"title": "Persistent Cross-Site Scripting (XSS)",
"target": "user"
possible values: user, server, database, data