Nov. 18, 2025
A consolidated overview of real-world vulnerabilities identified across web and API assessments
binsec GmbH has consolidated the results of all web penetration tests (including connected APIs) conducted over the past twelve months. The data provides a clear picture of the vulnerability categories that appear most frequently in practice.
A significant portion of the findings relates to basic configuration weaknesses, such as insecure web server defaults, missing security headers, or inadequately configured TLS parameters. These issues are easy to identify and typically do not represent an immediate critical risk.
Session ManagementSession handling weaknesses continue to occur regularly. A common pattern is that logging out removes the session only in the browser, while the server-side session remains active. This allows continued use of a previously compromised session.
Authorization and Access ControlMost critical findings stem from incomplete or faulty access control mechanisms. This includes privilege escalation paths, missing object- or tenant-level isolation, and insufficient protection of API endpoints. Modern applications with extensive background API communication are particularly affected, as access controls often need to be implemented manually.
Classic VulnerabilitiesSQL injection and cross-site scripting (XSS) are less common today but still appear in practice – especially in areas where safeguards such as ORMs, input validation, or prepared statements are bypassed or not applied consistently.
Business Logic IssuesBusiness logic vulnerabilities occur infrequently, but when identified, they typically have a significant impact because they directly affect critical application workflows.
Talk now
to our
Pentest experts.
Contact us
OSCP, M.Sc. Security Management
Talk now to our Pentest experts.
OSCP, M.Sc. Security Management
Penetration Testing
Since 2013 we conduct professional penetration test, based on international industry standards and years of experience in penetration testing, red teaming and hacking.
As a company for professional penetration testing, we do some things differently than other pentest provider: As a penetration test firm, we do not sell vulnerability scans as pentest. We do also focus on business security risks. You are looking for a professionally conducted penetration tests? Get the binsec team for your Pentest. Read more about our pentest service.
Contact us