Disabled or incorrectly used protection mechanism can make the application vulnerable to security issues like cross-site scripting (XSS) attack, clickjacking, etc.