The most-rewarded flaw is XSS, which is among those that are relatively cheap for organizations to identify.
Source: Threadpost