Content is hidden
Open Redirect
Remote Code Execution (RCE)
Account Enumeration
No Rate Limiting on Form
Cross-site Scripting (XSS) - Stored
Brute Force