Content is hidden
Open Redirect
Sensitive Data Exposure
Remote Code Execution (RCE)
Command Injection
DoS with (Unexpected) revert
Spoof HTML Content
Code Injection
Broken Access Control (BAC)
Application-Level Denial-of-Service (DoS)
Improper Authentication