Open Redirect

Occurs when a site redirects e.g. to a value of a query parameter without any validation (leaving for a different domain). This can lead to an increased risk of phishing attacks.

Shopify is an example to go to. Also, remember that each new service a site uses represents a potential attack vector, such as this Zendesk misuse on HackerOne.

