Accept file uploads safely
The feature most likely to be your first security incident.
Users need to upload <what kind of file>, up to <size>. Implement it with these checks spelled out: - Size limit enforced on the server, not just the form. - Type checked by actual content, not by the filename extension. - Stored with a name I generate, never the name the user sent. - Stored somewhere it cannot be executed or served as HTML. Tell me what an attacker would try here and which check stops it.
An upload form is a stranger writing files onto your server. Every one of those rules exists because someone skipped it.