Server-Side Security: Authorisation Is the Weak Point
Injection grabs attention, and authorisation causes breaches. Broken access control has been the top web application risk for four consecutive editions, and it's found in essentially every application tested.