Application/Business Logic
Reflective XSS
SQL Injection
Information leak/disclosure
Deserialization
Stored XSS