Payloads All The Things - Command Injection
Cross Site scripting:
If user input data is bieng rendered to the page, this could open up XSS possibilities:
can you inject commands into data being sent in the requests?
can you submit html with javascript in attributes in form submissions?