HomeSecurity86% of PHP-based applications have XSS vulnerability

86% of PHP-based applications have XSS vulnerabilities

Four out of five applications written in PHP, Classic ASP and ColdFusion that were evaluated by Veracode failed at least one of the top 10 OWASP (Open Web Application Security Project) tests shown below.

PHP

Given the volume of PHP- based applications for the three most popular content management systems, WordPress , Joomla and Drupal , which account for 70% of all systems, the findings raise concerns about potential security issues on millions of websites.

Statistics show that 86% of PHP applications contain at least one Cross-Site Scripting (XSS) vulnerability and 56% have at least one SQL injection when initially tested by Veracode. These vulnerability trends are also observed in the broader family of web programming languages, where applications written in Classic ASP and ColdFusion are twice as likely to have these flaws compared to more modern .NET and Java.

As businesses increasingly invest in innovative applications, the pressure to create more secure software intensifies. However, less than 26% of organizations have mandated ongoing secure coding training programs.

Language design matters for security. Some languages ​​are designed from the ground up to avoid certain classes of vulnerabilities. For example, by removing the need for programmers to directly allocate memory, Java has almost completely eliminated vulnerabilities related to memory allocation (such as memory overflows).

The language's runtime environment also matters for security. Some vulnerabilities only appear in certain runtime environments. For example, some types of information leaks are more common on mobile.

Mobile app development teams need to focus on encryption. 87% of Android apps and 80% of iOS apps have cryptographic issues. This suggests that while mobile app developers may be aware of the need for encryption to protect sensitive information and thus use it in their apps, few of them know how to implement it properly.

While no technology alone is sufficient to provide security to an application, understanding the strengths and weaknesses of each technology is very important for fixing software vulnerabilities.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS