Stored XSS
Application/Business Logic
Auth issues
Information leak/disclosure
RCE
Deserialization
Open Redirect
Reflective XSS
SQL Injection