In the OWASP Top 10 (2013 update), Security Misconfiguration and Unvalidated Redirects were newly added entries. Security Misconfiguration (A2013:6) addresses improper security settings. Unvalidated Redirects (A2013:10) covers unsafe URL forwards. Insecure Direct Object References and CSRF were in previous versions but not new additions.