Content is hidden
Plaintext Password Field
Weak Registration Implementation
Insecure Authorization
Business Logic Errors
Unsecure Design
Cross-Site Request Forgery (CSRF)
Lack of Rate Limiting Protections (i.e. CAPTCHA)
Other
Authenticated Action
Token Leakage via Referer