Content is hidden
Lack of Rate Limiting Protections (i.e. CAPTCHA)
Other
OAuth Misconfiguration
Cross-site scripting XSS
Subdomain Takeover
Privilege Escalation
Unsafe File Upload
Race Conditions
Insecure Direct Object Reference (IDOR)
Improper Access Control