I make this mistake in some of my own side projects, but...
When you are building user registration for a for an online service, take care that you aren't leaking membership information. Like if I try to sign up with an email (or do a password reset) and that email is already taken, don't tell me the email was already taken. Say "If this email address is available, you will get an email with a confirmation link."
That sort of thing.
It's not necessarily a huge security vulnerability, but it protects your users' privacy by not revealing that they've signed up for your service.