- Unauthenticated Export, leading to disclosure of subscribers data - Insecure Permissions on Dashboard and Settings - CSRF on Settings - Send Test Emails from the Administrative Dashboard as an Authenticated User (with a role of Subscriber and above) - Unauthenticated Option Creation