Common Findings in Web Penetration Tests

Nov. 18, 2025

A consolidated overview of real-world vulnerabilities identified across web and API assessments

binsec GmbH has consolidated the results of all web penetration tests (including connected APIs) conducted over the past twelve months. The data provides a clear picture of the vulnerability categories that appear most frequently in practice.

Configuration Issues

A significant portion of the findings relates to basic configuration weaknesses, such as insecure web server defaults, missing security headers, or inadequately configured TLS parameters. These issues are easy to identify and typically do not represent an immediate critical risk.

Session Management

Session handling weaknesses continue to occur regularly. A common pattern is that logging out removes the session only in the browser, while the server-side session remains active. This allows continued use of a previously compromised session.

Authorization and Access Control

Most critical findings stem from incomplete or faulty access control mechanisms. This includes privilege escalation paths, missing object- or tenant-level isolation, and insufficient protection of API endpoints. Modern applications with extensive background API communication are particularly affected, as access controls often need to be implemented manually.

Classic Vulnerabilities

SQL injection and cross-site scripting (XSS) are less common today but still appear in practice – especially in areas where safeguards such as ORMs, input validation, or prepared statements are bypassed or not applied consistently.

Business Logic Issues

Business logic vulnerabilities occur infrequently, but when identified, they typically have a significant impact because they directly affect critical application workflows.

Talk now
to our
Pentest experts.

Contact us
Patrick Sauer, OSCP, M.Sc. Security Management
Patrick Sauer, CEO
OSCP, M.Sc. Security Management

Talk now to our Pentest experts.

Patrick Sauer, CEO
Patrick Sauer, CEO
OSCP, M.Sc. Security Management
Contact us

Penetration Testing

Since 2013 we conduct professional penetration test, based on international industry standards and years of experience in penetration testing, red teaming and hacking.

As a company for professional penetration testing, we do some things differently than other pentest provider: As a penetration test firm, we do not sell vulnerability scans as pentest. We do also focus on business security risks. You are looking for a professionally conducted penetration tests? Get the binsec team for your Pentest. Read more about our pentest service.

Contact us

Pentest Knowledge and Tools

Free pentest tools for your security analysis.

Pentest Tools

Take a look at our wiki page about pentesting.

Pentest WIKI

Straight answers to common pentesting questions.

Pentest FAQ

News about pentesting and the binsec universe.

Pentest News

Company

binsec GmbH
Solmsstraße 41
60486 Frankfurt am Main
Germany

Legal notice

Director: Patrick Sauer
Authorised Officer: Florian Zavatzki, Dominik Sauer
Registration: Frankfurt am Main, HRB97277
Turnover Tax Identification No.: DE290966808

© 2025 All rights reserved by binsec GmbH.

© 2025 All rights reserved by binsec GmbH.