OWASP line
A03: SQL injection, XSS (stored/reflected/DOM), command & template injection, CSP
4 sections