# Top Web Vulnerabilities

> Provide a comprehensive, structured reference for the 100 most critical web application vulnerabilities organized by category. This skill enables systematic vulnerability identification, impact assessment, and remediation guidance across the full spectrum of web security threats.

- Skill: `newmindsgroup/top-web-vulnerabilities` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add newmindsgroup/top-web-vulnerabilities`
- Raw SKILL.md: https://api.skillmd.com/api/skills/newmindsgroup/top-web-vulnerabilities/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- License: MIT
- Author: newmindsgroup (https://skillmd.com/u/newmindsgroup)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/newmindsgroup/top-web-vulnerabilities

---


# Top 100 Web Vulnerabilities Reference

Provide a comprehensive, structured reference for the 100 most critical web application vulnerabilities organized by category. This skill enables systematic vulnerability identification, impact assessment, and remediation guidance across the full spectrum of web security threats.

## When to Use
- This skill is applicable to execute the workflow or actions described in the overview.

## Core Workflow
1. Confirm the request matches this skill's trigger, scope, and risk profile.
2. Use the topic map to identify the relevant pattern, checklist, or example before writing detailed guidance or code.
3. Load `references/full-guidance.md` when implementation details, examples, anti-patterns, validation checks, or edge cases are needed.
4. Apply only the relevant guidance instead of loading or repeating the entire reference by default.
5. Verify the result against any validation checks, limitations, security notes, or platform constraints in the reference.

## Topic Map
- Purpose
- Prerequisites
- Outputs and Deliverables
- Core Workflow
- Phase 1: Injection Vulnerabilities Assessment
- Phase 2: Authentication and Session Security
- Phase 3: Sensitive Data Exposure
- Phase 4: Security Misconfiguration
- Phase 5: XML-Related Vulnerabilities
- Phase 6: Broken Access Control
- Phase 7: Insecure Deserialization
- Phase 8: API Security Assessment
- Phase 9: Communication Security
- Phase 10: Client-Side Vulnerabilities
- Phase 11: Denial of Service Assessment
- Phase 12: Server-Side Request Forgery
- Phase 13: Additional Web Vulnerabilities
- Phase 14: Mobile and IoT Security

## Reference Map
- `references/full-guidance.md` preserves the complete original guidance, including examples and detailed edge cases.

## Progressive Loading
Keep this `SKILL.md` as the compact routing and workflow entrypoint. Load the reference file only when the user task requires the deeper implementation material.

