Email/Username enumeration
CSRF
Email spoofing in email confirmation