Open research questions in Web Application Security Vulnerabilities
56 unresolved questions extracted from the limitations and future-work sections of 180 Web Application Security Vulnerabilities papers in our library. Each links back to the study that raised it.
What the literature leaves open
The challenge is to detect advanced or unknown threats. The challenge is to reduce false alerts while ensuring real threats are not missed. The challenge is to provide a reliable, scalable, and easy-to-maintain solution for modern network environments.
Cyberattacks such as phishing, brute-force attacks, credential stuffing, session hijacking, and replay attacks. Weak password practices and password reuse. The need for a scalable and secure authentication mechanism that balances security strength, usability, and performance efficiency.
The lack of a methodology to compare libraries across ecosystems. The need to distinguish libraries that are highly exposed to the Internet from those that are not. The need to select libraries that are representative of the ecosystem.
Integrating online payment gateways. Developing a mobile application for SecureX. Enhancing the administrative dashboard with business-intelligence layers and revenue analytics.
The lack of a centralized platform for security service booking and management. The inefficiencies of manual coordination methods. The need for a user-friendly interface for customers and a centralized platform for administrators.
Insecure coding practices. Lack of proper input validation. Weak access control mechanisms.
A Study on Forensic Reconstruction of Web Application Attacks in a Controlled Xampp Environment · 2026 · DOIFuture research can focus on implementing the recommended improvements. Future research can focus on evaluating the security of other web-based systems in the education sector.
Security Evaluation of the TIF Dashboard Using the Penetration Testing Execution Standard (PTES) Methodology · 2026 · DOIThe study identifies a gap in the existing research on web application security in the education sector. The study highlights the need for regular security evaluations for web-based systems.
Security Evaluation of the TIF Dashboard Using the Penetration Testing Execution Standard (PTES) Methodology · 2026 · DOIKey limitations of the existing system include lack of integration, high cost, complexity, and time consumption. The existing system requires multiple tools, increasing complexity, and many advanced tools require expensive licenses.
The existing system has limitations including lack of integration, high cost, complexity, and time consumption. There is a need for an automated and integrated solution for vulnerability scanning.
Further evaluation of the proposed system in different scenarios and environments. Investigation of other machine learning algorithms for anomaly detection. Development of more advanced threat detection techniques.
Traditional security mechanisms are not able to detect new or unknown threats. The lack of a hybrid approach that combines rule-based detection with AI-based anomaly detection. The need for a scalable and industrially applicable framework for safeguarding cloud-based ecosystems.
The lack of secure and scalable authentication mechanisms in digital traffic offense management systems. The vulnerability of single-factor authentication strategies to credential theft and phishing. The need for a novel Multi-Factor Authentication framework that integrates knowledge-based, possession-based, and inherence-based authentication levels.
A Secure Multi-Factor Authentication Framework for Digital Traffic Offense Management Systems · 2026 · DOIThe study was conducted in a controlled environment, which may not reflect real-world scenarios. The experiments were limited to intentionally vulnerable web applications and a local server environment.
Further research is needed to develop more adaptive and layered security approaches. The development of more effective detection systems for advanced SQL injection techniques is necessary.
Many web applications remain vulnerable to cyber threats due to insecure coding practices. There is a need for practical insights into the forensic reconstruction of web application attacks.
A Study on Forensic Reconstruction of Web Application Attacks in a Controlled Xampp Environment · 2026 · DOIThe gap is the limitation of traditional security tools in detecting advanced or unknown threats. The gap is the need for a more effective solution to improve network security.
The system was tested using a limited number of test cases. The system was developed for a specific use case and may not be generalizable to other domains.
FitZone GYM Membership System: A Secure-by-Design Web Application Following the Secure Software Development Lifecycle · 2026 · DOIAdvanced session management features such as expiration, HttpOnly/Secure cookie attributes can be implemented. The system can be integrated with existing gym management software to provide an additional layer of security.
FitZone GYM Membership System: A Secure-by-Design Web Application Following the Secure Software Development Lifecycle · 2026 · DOIThe paper identifies a gap in the existing research on progressive web application architecture, particularly in the area of security. It highlights the need for a holistic perspective that integrates technical analyses with organizational and practical considerations.
Basic-block abstraction for JavaScript taint. Adapting AirTaint's granularity reduction mechanism for JavaScript.
Existing solutions have limitations in detecting DOM-XSS vulnerabilities. There is a need for a more effective approach to detect DOM-XSS vulnerabilities. Current solutions can't handle obfuscated attack payloads effectively.
The study uses a simulation-based research design, which may not fully capture real-world scenarios. The sample size is limited to 1,000 authentication attempts.
Evaluating the attack on a large scale. Developing security mechanisms to prevent task-aligned injection attacks. Exploring the potential risks of using LLMs in web-use agents.
The security of web-use agents has not been thoroughly explored. The attack surface of web-use agents bypasses traditional browser security mechanisms.
Most-cited papers in Web Application Security Vulnerabilities
- LLMs Cannot Reliably Identify and Reason About Security Vulnerabilities (Yet?): A Comprehensive Evaluation, Framework, and Benchmarks · 2024 · 89 citations
- GraphXSS: An efficient XSS payload detection approach based on graph convolutional network · Computers & Security · 2021 · 36 citations
- Cluster‐analysis attack against a PRivAte Web solution (PRAW) · Online Information Review · 2006 · 14 citations
- Application Programming Interface (API) Security in Cloud Applications · EAI Endorsed Transactions on Cloud Systems · 2023 · 12 citations
- European digital libraries: web security vulnerabilities · Library Hi Tech · 2010 · 11 citations
- A Novel Approach for Semantic Web Application in Online Education Based on Steganography · International Journal of Web-Based Learning and Teaching Technologies · 2021 · 11 citations
- Enhancing Burp Suite with Machine Learning Extension for Vulnerability Assessment of Web Applications · Journal of Applied Security Research · 2022 · 10 citations
- Denial-of-Service Attack · International Journal of Information Security and Cybercrime · 2021 · 7 citations
- A Scrutiny of Honeyword Generation Methods: Remarks on Strengths and Weaknesses Points · Cybernetics and Information Technologies · 2022 · 5 citations
- Enhanced Identity and Access Management with Artificial Intelligence: A Strategic Overview · International Journal of Information Security and Cybercrime · 2024 · 5 citations
Most recent work
- Trace Gadgets: Minimizing Code Context for Machine Learning-Based Vulnerability Prediction · 2026
- ARTIFICIAL INTELLIGENCE–BASED PROTECTION METHODS AGAINST SQL INJECTION IN RELATIONAL DATABASES · Zenodo (CERN European Organization for Nuclear Research) · 2026
- Security Based Question Paper Generation · International Scientific Journal of Engineering and Management · 2026
- WebSentinel: A Passive In-Browser Framework for Real-Time Web Vulnerability Detection · INTERNATIONAL JOURNAL OF SCIENTIFIC RESEARCH IN ENGINEERING AND MANAGEMENT · 2026
- Modern Authentication Mechanisms in Web Applications: A Comparative Study · International Scientific Journal of Engineering and Management · 2026
- CASB-Driven Browser Extension for Data Leakage Prevention · INTERNATIONAL JOURNAL OF SCIENTIFIC RESEARCH IN ENGINEERING AND MANAGEMENT · 2026
- Security Evaluation of the TIF Dashboard Using the Penetration Testing Execution Standard (PTES) Methodology · Engineering and Technology Journal · 2026
- Vulnerability Scanner using Python · International Journal of Science, Strategic Management and Technology · 2026
- An Adaptive Hybrid Intelligence System for API Abuse and Data Exposure Detection · International Research Journal on Advanced Engineering Hub (IRJAEH) · 2026
- A Secure Multi-Factor Authentication Framework for Digital Traffic Offense Management Systems · Iconic Research and Engineering Journals · 2026
Find a gap in your own Web Application Security Vulnerabilities sub-topic
This page shows what the Web Application Security Vulnerabilities literature already flags as unresolved. To narrow it to your specific question, run the guided finder — it searches the gap library on demand and checks candidates against 250M+ OpenAlex works.
Open the Research Gap Finder →