Computer Science · Research topic

Open research questions in Web Application Security Vulnerabilities

56 unresolved questions extracted from the limitations and future-work sections of 180 Web Application Security Vulnerabilities papers in our library. Each links back to the study that raised it.

What the literature leaves open

  • The challenge is to detect advanced or unknown threats. The challenge is to reduce false alerts while ensuring real threats are not missed. The challenge is to provide a reliable, scalable, and easy-to-maintain solution for modern network environments.

    Penetration Testing And Network Attack Detection System · 2026 · DOI
  • Cyberattacks such as phishing, brute-force attacks, credential stuffing, session hijacking, and replay attacks. Weak password practices and password reuse. The need for a scalable and secure authentication mechanism that balances security strength, usability, and performance efficiency.

    Secure Authentication Mechanism for Web Application · 2026 · DOI
  • The lack of a methodology to compare libraries across ecosystems. The need to distinguish libraries that are highly exposed to the Internet from those that are not. The need to select libraries that are representative of the ecosystem.

    A methodology to perform cross-ecosystems case-control security studies · 2026 · DOI
  • Integrating online payment gateways. Developing a mobile application for SecureX. Enhancing the administrative dashboard with business-intelligence layers and revenue analytics.

    SecureX: A CCTV & Security Service Booking and Management System — Technical Report · 2026 · DOI
  • The lack of a centralized platform for security service booking and management. The inefficiencies of manual coordination methods. The need for a user-friendly interface for customers and a centralized platform for administrators.

    SecureX: A CCTV & Security Service Booking and Management System — Technical Report · 2026 · DOI
  • Insecure coding practices. Lack of proper input validation. Weak access control mechanisms.

    A Study on Forensic Reconstruction of Web Application Attacks in a Controlled Xampp Environment · 2026 · DOI
  • Future research can focus on implementing the recommended improvements. Future research can focus on evaluating the security of other web-based systems in the education sector.

    Security Evaluation of the TIF Dashboard Using the Penetration Testing Execution Standard (PTES) Methodology · 2026 · DOI
  • The study identifies a gap in the existing research on web application security in the education sector. The study highlights the need for regular security evaluations for web-based systems.

    Security Evaluation of the TIF Dashboard Using the Penetration Testing Execution Standard (PTES) Methodology · 2026 · DOI
  • Key limitations of the existing system include lack of integration, high cost, complexity, and time consumption. The existing system requires multiple tools, increasing complexity, and many advanced tools require expensive licenses.

    Vulnerability Scanner using Python · 2026 · DOI
  • The existing system has limitations including lack of integration, high cost, complexity, and time consumption. There is a need for an automated and integrated solution for vulnerability scanning.

    Vulnerability Scanner using Python · 2026 · DOI
  • Further evaluation of the proposed system in different scenarios and environments. Investigation of other machine learning algorithms for anomaly detection. Development of more advanced threat detection techniques.

    An Adaptive Hybrid Intelligence System for API Abuse and Data Exposure Detection · 2026 · DOI
  • Traditional security mechanisms are not able to detect new or unknown threats. The lack of a hybrid approach that combines rule-based detection with AI-based anomaly detection. The need for a scalable and industrially applicable framework for safeguarding cloud-based ecosystems.

    An Adaptive Hybrid Intelligence System for API Abuse and Data Exposure Detection · 2026 · DOI
  • The lack of secure and scalable authentication mechanisms in digital traffic offense management systems. The vulnerability of single-factor authentication strategies to credential theft and phishing. The need for a novel Multi-Factor Authentication framework that integrates knowledge-based, possession-based, and inherence-based authentication levels.

    A Secure Multi-Factor Authentication Framework for Digital Traffic Offense Management Systems · 2026 · DOI
  • The study was conducted in a controlled environment, which may not reflect real-world scenarios. The experiments were limited to intentionally vulnerable web applications and a local server environment.

    Detection and Prevention of SQL Injection Attacks in Modern Web Applications · 2026 · DOI
  • Further research is needed to develop more adaptive and layered security approaches. The development of more effective detection systems for advanced SQL injection techniques is necessary.

    Detection and Prevention of SQL Injection Attacks in Modern Web Applications · 2026 · DOI
  • Many web applications remain vulnerable to cyber threats due to insecure coding practices. There is a need for practical insights into the forensic reconstruction of web application attacks.

    A Study on Forensic Reconstruction of Web Application Attacks in a Controlled Xampp Environment · 2026 · DOI
  • The gap is the limitation of traditional security tools in detecting advanced or unknown threats. The gap is the need for a more effective solution to improve network security.

    Penetration Testing And Network Attack Detection System · 2026 · DOI
  • The system was tested using a limited number of test cases. The system was developed for a specific use case and may not be generalizable to other domains.

    FitZone GYM Membership System: A Secure-by-Design Web Application Following the Secure Software Development Lifecycle · 2026 · DOI
  • Advanced session management features such as expiration, HttpOnly/Secure cookie attributes can be implemented. The system can be integrated with existing gym management software to provide an additional layer of security.

    FitZone GYM Membership System: A Secure-by-Design Web Application Following the Secure Software Development Lifecycle · 2026 · DOI
  • The paper identifies a gap in the existing research on progressive web application architecture, particularly in the area of security. It highlights the need for a holistic perspective that integrates technical analyses with organizational and practical considerations.

    Progressive Web Application Architecture · 2026 · DOI
  • Basic-block abstraction for JavaScript taint. Adapting AirTaint's granularity reduction mechanism for JavaScript.

    Taintaru: DOM-based XSS Detection using Taint Tracking · 2026 · DOI
  • Existing solutions have limitations in detecting DOM-XSS vulnerabilities. There is a need for a more effective approach to detect DOM-XSS vulnerabilities. Current solutions can't handle obfuscated attack payloads effectively.

    Taintaru: DOM-based XSS Detection using Taint Tracking · 2026 · DOI
  • The study uses a simulation-based research design, which may not fully capture real-world scenarios. The sample size is limited to 1,000 authentication attempts.

    Secure Authentication Mechanism for Web Application · 2026 · DOI
  • Evaluating the attack on a large scale. Developing security mechanisms to prevent task-aligned injection attacks. Exploring the potential risks of using LLMs in web-use agents.

    Mind the Web: The Security of Web Use Agents · 2026 · DOI
  • The security of web-use agents has not been thoroughly explored. The attack surface of web-use agents bypasses traditional browser security mechanisms.

    Mind the Web: The Security of Web Use Agents · 2026 · DOI

Most-cited papers in Web Application Security Vulnerabilities

Most recent work

Find a gap in your own Web Application Security Vulnerabilities sub-topic

This page shows what the Web Application Security Vulnerabilities literature already flags as unresolved. To narrow it to your specific question, run the guided finder — it searches the gap library on demand and checks candidates against 250M+ OpenAlex works.

Open the Research Gap Finder →

Related topics in Computer Science

56 open questions have been extracted from the limitations and future-work passages of 180 Web Application Security Vulnerabilities papers in our library. Each one below links back to the study that raised it, so you can read the original claim in context.

Tools for your next paper

Compare the categoryHonest roundups of the AI research tools, ours listed alongside the alternatives.

Command palette

Jump anywhere, run any action.