Reflective XSS
Auth issues
Stored XSS
SQL Injection
Open Redirect
Application/Business Logic
Information leak/disclosure
Deserialization