I wanted to test the ZAP automation framework, so I used two Docker container to run ZAP against the OWASP Juiceshop. I found a total of 14 (2 high, 4 medium, 4 low, 4 informational) "vulnerabilities". For me that did not sound convincing, so I wanted to know, what results you got in similar tests and what I could adapt in order to get better results.
Greetings,
Paul