Unauthenticated stored XSS in server-log delivered via username field from login-form
CSRF-token exposed in javascript, makes it possible to get a valid CSRF-Token and use it in XMLHTTPRequests. Using CSRF to add task, that runs commands on server as "NT-System"