1. Session does not expire on closing the browser
2. Application is vulnerable to HTML injection attack
3. Dangerous HTTP methods are enabled on the server
4. Sensitive data is accessible from cache
5. Sensitive information revealed in HTTP response
6. Application is vulnerable to stored Cross Site Scripting attack
7. Application is vulnerable to CSRF attack
8. Application accepts special characters as user inputs
9. Auto-complete is enabled for sensitive fields
10. Server Side input validations are not in place
11. DOS using sql wildcards