Application/Business Logic
Auth issues
Reflective XSS
Information leak/disclosure
Deserialization
Stored XSS
SQL Injection
Open Redirect
RCE