The OWASP Top 10 Application Security Risks
- Injection
- Cross-Site Scripting (XSS) or here
- Broken Authentication and Session Management
- Insecure Direct Object References
- Cross-Site Request Forgery (CSRF)
- Security Misconfiguration*
- Insecure Cryptographic Storage
- Failure to Restrict URL Access
- Insufficient Transport Layer Protection*
- Unvalidated Redirects and Forwards
*May be outside the developer’s control
Read more here
Tham khảo http://securitydaily.net