Full threadA_No_Name_Mouse·I'd start with the OWASP top 10, https://owasp.org/Top10/ Depending on your tech stack and funtionality you could try SQL injection, CSRF or path traversal.View on HN