- Cross Site Scripting
- HTML injection
- Open redirect
- Authentication Bypass
- No Rate Limiting
- Race Condition
- Information Disclosure
- Using Default Credentials
- SQL injection
- Local File Inclusion
- Remote Code Execution
- Server-Side Template Injection
- Server-Side Request Forgery