The Open Web Application Security Project released a report on what they think are the top ten security vulnerabilities in web applications. You can get the report here:
http://prdownloads.sourceforge.net/owasp/OWASPWebApplicationSecurityTopTen-Version1.pdf?download
I’ve put together recommendations on how to avoid making those top ten mistakes if you’re coding in PHP. You can get that document here:

