Web Application Penetration Testing
Manual and automated testing of your web applications, APIs and single-page apps against the OWASP Web Security Testing Guide and Application Security Verification Standard. Findings include reproduction steps, CVSS 3.1 ratings and a free re-test of fixes within 90 days.
Beyond OWASP Top 10: How We Actually Test
Every consultancy quotes the OWASP Top 10. The Top 10 is a starting awareness document, not a methodology. The methodology that drives a real engagement is the OWASP Web Security Testing Guide (WSTG) v4.2 for procedure and the Application Security Verification Standard (ASVS) v4.0 for the depth and breadth of controls verified. We test against ASVS Level 2 by default and Level 3 for applications handling regulated or high-value data.
Automated scanners catch a fraction of what an attacker would. The findings that actually cause breaches — broken object-level authorisation (IDOR), business logic flaws, multi-step injection chains, SSRF pivots into cloud metadata, JWT algorithm confusion — are invisible to scanners. We use scanners for coverage and humans for the work that matters.
Vulnerability Classes We Test
Injection & RCE
SQL, NoSQL (MongoDB, Redis), LDAP, XPath, OS command, SSTI (Jinja/Twig/Razor), header injection, deserialisation chains in Java / .NET / PHP / Python / Ruby, and prototype pollution in JavaScript runtimes.
Authentication & Session
Password policy, account enumeration, brute-force resistance, MFA bypass, SAML and OAuth/OIDC flow abuse, JWT algorithm confusion and kid-header injection, session fixation, and refresh-token handling.
Access Control (IDOR & BOLA)
Horizontal and vertical privilege escalation, broken object-level authorisation (the #1 OWASP API risk), function-level authorisation gaps, and indirect-object reference flaws across REST resources, GraphQL nodes and signed URLs.
SSRF & Server-Side Logic
Server-side request forgery into cloud metadata (IMDSv1, GCP/Azure equivalents), internal service enumeration, request smuggling (HTTP/1.1 desync, HTTP/2 downgrade), cache poisoning, and host-header injection.
Client-Side & SPA
Stored, reflected and DOM-based XSS, postMessage abuse, CORS misconfiguration, CSP bypass, client-side prototype pollution leading to gadget chains, and framework-specific issues in React, Vue, Angular and Svelte.
Business Logic
Race conditions in payment and provisioning flows, negative-quantity and integer-overflow abuse, multi-step workflow bypass, currency / FX manipulation, coupon stacking, and discounting-engine flaws unique to your application.
APIs & GraphQL
Most modern web applications are predominantly API-driven. We test REST APIs against the OWASP API Security Top 10 and GraphQL endpoints against the GraphQL-specific risk catalogue — introspection enumeration, query depth/complexity abuse, batching attacks, alias-based rate-limit bypass, and field-level authorisation gaps. For a dedicated API engagement see our API Security Testing service.
Frameworks We Know Inside-Out
Generic web testing assumes a generic web app. Real applications are built on opinionated frameworks with their own pitfalls. Our team has shipped engagements against Next.js (App Router and Pages Router), Django, Rails, Spring Boot, Laravel, Express, FastAPI, ASP.NET Core and the major SPA frameworks. Knowing the framework means knowing where it lets you down by default — Next.js Server Actions, Django middleware ordering, Spring expression language, Rails mass-assignment, etc.
Engagement Output
- Executive summary — one-page board-ready narrative covering risk posture, headline findings and recommended action.
- Technical findings — each finding with CVSS 3.1 base + temporal score, OWASP category, CWE reference, reproduction steps with screenshots and HTTP requests, and remediation guidance specific to your stack.
- Coverage matrix — the WSTG / ASVS controls we tested, with pass/fail evidence, so future testing is comparable year-over-year.
- Re-test of fixes — included free of charge within 90 days. Every finding closed gets an explicit verification entry; partial fixes get explicit residual-risk notes.
- Compliance-ready letter — for SOC 2, ISO 27001, PCI DSS, Cyber Essentials Plus and customer-facing security questionnaires.
Related Services
- API Security Testing — dedicated REST and GraphQL API engagements.
- Mobile Application Security Testing — iOS and Android testing for paired mobile clients.
- Cloud Security Assessment — for the underlying AWS / Azure / GCP estate.
- All Penetration Testing Services — the full CDSEC service catalogue.
Scope a Web Application Pen Test
Most web application engagements scope in under 30 minutes. Tell us the technology stack, rough page/endpoint count, authentication model and any compliance driver, and we'll come back with a fixed-price proposal in 24 hours.
Get a QuoteGet In Touch
Ready to secure your business? Contact our team of certified experts today for a consultation.
Contact Us
Get in touch for questions about our services
Phone
+44131 460 4180
Speak directly with our security experts
Our Global Offices
Local expertise with global reach across three continents