Security analysis of selected web applications using vulnerability scanners
Article Sidebar
Issue Vol. 40 (2026)
-
Analysis of the capabilities of predictive artificial intelligence models in corporate risk management
Kacper Ziemski188-192
-
Usability and availability of selected e-commerce services
Marcin Kozicki, Maria Skublewska-Paszkowska193-200
-
Comparison of C++ and Python performance based on selected algorithms
Szymon Bogucki, Kacper Burda201-205
-
Security analysis of selected web applications using vulnerability scanners
Mariusz Choroś, Marta Dziuba-Kozieł206-212
-
Comparison of Java and .NET reflection mechanisms for dynamic module loading: a performance benchmark study
Michał Mazur, Sebastian Maruszak, Marek Miłosz213-217
-
Comparative analysis of network vulnerability detection tools
Mateusz Zdunek218-225
-
Evaluation of mobile applications for personal finance management using the MARS scale
Łukasz Nikiel, Artsiom Patskevich, Marek Miłosz226-231
-
Comparison of the effectiveness of roulette betting strategies using Monte Carlo simulation
Marek Sarnecki232-238
-
Analysis of optimization capabilities of selected database management systems
Paweł Tarkiewicz, Małgorzata Plechawska-Wójcik239-246
-
Comparative analysis of Espresso and Appium frameworks for automated UI testing of Android mobile applications
Jakub Derkacz247-254
-
Comparative analysis of the applicability of artificial intelligence models for code generation
Patryk Warchoł, Małgorzata Plechawska-Wójcik255-262
-
Comparison of the effectiveness of selected tools for detecting texts generated by artificial intelligence
Marcin Brodacki, Małgorzata Plechawska-Wójcik263-269
-
Comparative analysis of selected containerization tools in terms of MCP
Paweł Jan Tłusty, Maciej Pańczyk270-276
-
SpikeCliff effect: empirical analysis of deterministic timing discontinuities in sponge-based XOF functions
Łukasz Wójcik, Stanisław Lota277-282
-
Comparison of AI agents for creating SQL queries
Julia Sierpień, Maria Skublewska-Paszkowska283-288
-
Comparative analysis of the performance of PostgreSQL and Neo4j databases in the context of genealogical queries
Michał Muzyka, Mateusz Niedźwiedź, Marek Miłosz289-296
-
Evaluation of the effectiveness of static and dynamic methods in malware analysis
Dominik Tracz, Daniel Sawicki, Konrad Gromaszek297-303
-
Comparison of classical machine learning methods in the task of obesity level classification
Paweł Biesaga, Paweł Powroźnik304-312
Main Article Content
Authors
Abstract
Web applications are among the most frequently targeted systems in today’s cyber-threat landscape, and vulnerabilities such as SQL injection, cross-site scripting and various configuration errors have dominated the OWASP Top 10 list for years. This article examines the security of a web application using modern vulnerability scanning tools and penetration testing. The study was conducted in two stages: in the first stage, the deliberately vulnerable OWASP Juice Shop application was used, with three scanners: OWASP ZAP, Burp Suite Community Edition and Nuclei applied to it. In the second stage, the tools were used to assess the security of a proprietary web application. All tests were conducted in a local, controlled environment and utilised Docker containerisation for the deliberately vulnerable application. The results of the proprietary application assessment revealed no logical vulnerabilities from the OWASP Top 10 category. The tools did not confirm the presence of SQL Injection, XSS or Broken Access Control. The identified issues related solely to the configuration of HTTP security headers. The study confirms that none of the scanners used can detect the full spectrum of vulnerabilities on their own, and that a combination of automated, semi-automated and template-based scanning provides the most comprehensive assessment of web application security.
Keywords:
Sustainable Development Goal (SDG)
- Industry, Innovation, Technology and Infrastructure
- Peace, justice and strong institutions
References
[1] S. Qadir, E. Waheed, A. Khanum, S. Jehan, Com-parative evaluation of approaches & tools for ef-fective security testing of Web applications, PeerJ Computer Science 11 (2025) e2821, https://doi.org/10.7717/peerj-cs.2821.
[2] OWASP Top 10, https://owasp.org/Top10/2025/, [08.05.2026].
[3] S. Alazmi, D. Conte de Leon, A Systematic Litera-ture Review on the Characteristics and Effective-ness of Web Application Vulnerability, IEEE Ac-cess 10 (2022) 33200–33219, https://doi.org/10.1109/ACCESS.2022.3161522.
[4] J. Shahid, M.K. Hameed, I.T. Javed, K.N. Qureshi, M. Ali, N. Crespi, A Comparative Study of Web Application Security Parameters: Current Trends and Future Directions. Applied Sciences 12(8) (2022) 4077 https://doi.org/10.3390/app12084077.
[5] P. Zamościński, G. Kozieł, Analysis of security CMS platforms by vulnerability scanners. Journal of Computer Sciences Institute 15 (2020) 252-260, https://doi.org/10.35784/jcsi.2020.
[6] P. Jarupunphol, S. Seatun, W. Buathong, Measur-ing Vulnerability Assessment Tools Performance on the University Web Application, Pertanika Journal of Science & Technology, 31(6) (2023) 2973–2993, https://doi.org/10.47836/pjst.31.6.19.
[7] A. Kondraciuk, A. Bartos, B. Pańczyk, Compara-tive analysis of the effectiveness of OWASP ZAP, Burp Suite, Nikto and Skipfish in testing the secu-rity of web applications. Journal of Computer Sci-ences Institute 24 (2022) 176-180, https://doi.org/10.35784/jcsi.2929.
[8] Edgescan, 2024 Vulnerability Statistics Report, https://www.edgescan.com/wp-content/uploads/2025/04/2024-Vulnerability-Statistics-Report.pdf, [08.05.2026].
[9] OWASP Juice Shop, https://juice-shop.github.io/, [08.05.2026].
[10] M. Wisnu, B. Soewito, Security Assessment Based on OWASP Top 10 Using SonarQube and ZAP on Export and Import Applications in the LNSW, IN-TENSIF: Jurnal Ilmiah Penelitian dan Penerapan Teknologi Sistem Informasi 10(1) (2026) 36–52, https://doi.org/10.29407/intensif.v10i1.25294
Article Details
Abstract views: 3

