Earlier quoted context omitted.
I like it because it describes how specifically the vulnerabilities were found and what specifically they were. If you’re doing security review or building a secure tool there are 5 items for your checklist.
They are bad mistakes that should have never have passed QA. Think a bit. Pentesting only makes sense if you don't have a functional QA. Its like hiring a guy with a sledgehammer to test the stability of your bridge. You should hire a structural engineer instead, before building it. If the guy with the sledgehammer is successful, you should never have built the bridge in the first place.
QA doesn't find XSS, SQL injection, CSRF, IDOR