Insecure direct object reference
Application/Business Logic
Auth issues
Information leak/disclosure
Open Redirect
Reflective XSS
Stored XSS