Report: 9 Out Of 10 Web Sites Have Serious Security Vulnerabilities

WhiteHat Security recently announced the availability of the third WhiteHat Web site Security Statistics Report, which highlights the top 10 vulnerabilities currently affecting organizations. Attacks on Web sites are on the rise, placing intellectual property, customer data and brand integrity at risk.

The WhiteHat Security Statistics Report shows that nine out of 10 Web sites have serious vulnerabilities that make the sites targets for malicious online attacks. Cross-site Scripting (XSS) remains the top vulnerability class, appearing in approximately three quarters of Web sites, while Information Leakage is the top vulnerability class of the overall population. New attack techniques such as XSS-phishing, Intranet Hacking and Web worms may force enterprises to re-evaluate the criticality of XSS on a case-by-case basis. A new addition to WhiteHat's report includes a comparison of vulnerabilities across vertical markets, including a review of Web sites from retail, healthcare, financial services, IT and insurance industries.

The report statistics were gathered through the deployment of WhiteHat's Sentinel Service, an outsourced service providing Web site vulnerability assessments on an ongoing basis. With more than six hundred sites under management, including many of the Fortune 500, WhiteHat has access to an unparalleled amount of security data, which allows the Company to accurately identify which issues are the most prevalent and also trend across major vertical markets. WhiteHat Security uses the Web Application Security Consortium (WASC) Threat Classification as a baseline for classifying vulnerabilities.

Since the last report in April 2007, there has been a noticeable increase in several technical vulnerabilities including XSS, Information Leakage, SQL Injection and HTTP Response Splitting, which can be directly attributed to the discovery of new attack techniques and the improvement in vulnerability identification technology. The report revealed that HTTP Response Splitting has proven to be a hugely misunderstood and underestimated issue, evading most scanning technology since its discovery several years ago. The overall results are startling both in the prevalence and potential consequences of HTTP Response Splitting exploits.

WhiteHat Security also examined the ways in which Web site vulnerabilities are plaguing various vertical markets, finding that while Web site security remains generally weak, the retail sector has been performing better than other markets. XSS tops the list of vulnerability classes by vertical, followed closely by information leakage. WhiteHat found that while the security posture of some industries is stronger than others, the difference is insignificant when it comes to a Web site being compromised since hackers only need to exploit a single vulnerability to cause damage.

Featured

  • Report: 47 Percent of Security Service Providers Are Not Yet Using AI or Automation Tools

    Trackforce, a provider of security workforce management platforms, today announced the launch of its 2025 Physical Security Operations Benchmark Report, an industry-first study that benchmarks both private security service providers and corporate security teams side by side. Based on a survey of over 300 security professionals across the globe, the report provides a comprehensive look at the state of physical security operations. Read Now

    • Guard Services
  • Identity Governance at the Crossroads of Complexity and Scale

    Modern enterprises are grappling with an increasing number of identities, both human and machine, across an ever-growing number of systems. They must also deal with increased operational demands, including faster onboarding, more scalable models, and tighter security enforcement. Navigating these ever-growing challenges with speed and accuracy requires a new approach to identity governance that is built for the future enterprise. Read Now

  • Eagle Eye Networks Launches AI Camera Gun Detection

    Eagle Eye Networks, a provider of cloud video surveillance, recently introduced Eagle Eye Gun Detection, a new layer of protection for schools and businesses that works with existing security cameras and infrastructure. Eagle Eye Networks is the first to build gun detection into its platform. Read Now

  • Report: AI is Supercharging Old-School Cybercriminal Tactics

    AI isn’t just transforming how we work. It’s reshaping how cybercriminals attack, with threat actors exploiting AI to mass produce malicious code loaders, steal browser credentials and accelerate cloud attacks, according to a new report from Elastic. Read Now

  • Pragmatism, Productivity, and the Push for Accountability in 2025-2026

    Every year, the security industry debates whether artificial intelligence is a disruption, an enabler, or a distraction. By 2025, that conversation matured, where AI became a working dimension in physical identity and access management (PIAM) programs. Observations from 2025 highlight this turning point in AI’s role in access control and define how security leaders are being distinguished based on how they apply it. Read Now

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.