Web App Vuln Stats

Some stats about Web Application vulnerabilities from White Hat Security.

Around 30 percent of Websites are likely to contain content spoofing bugs
18 percent, insufficient authorization
17 percent, SQL injection
14 percent, predictable resource location
11 percent, session fixation
11 percent, cross-site request forgery (CSRF)
10 percent, insufficient authentication
9 percent, HTTP response-splitting flaws

To be fair and accurate, of course, these statistics apply to the sample group of White Hat Security customers, not the entire Internet.

