Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
@article{204952,
author = {Udit Agrawal and Md faiz},
title = {Security vulnerabilities in modern web frameworks},
journal = {International Journal of Innovative Research in Technology},
year = {2026},
volume = {13},
number = {1},
pages = {5050-5057},
issn = {2349-6002},
url = {https://ijirt.org/article?manuscript=204952},
abstract = {The way we develop web applications has changed dramatically since the introduction of front end frameworks like React and Angular, as well as back end frameworks such as Django, Laravel, and Express.js. With these frameworks, developers are able to use advanced routing systems, state management tools, and built in access control functionality to create applications quickly and consistently. In addition to providing these features and helping to standardize design patterns, these frameworks also allow developers to develop more efficiently. This means faster development cycles and less need for ongoing code maintenance. Even though the majority of web applications created with the above mentioned frameworks include basic inbuilt security functionalities, the applications may still be vulnerable to high levels of risk. These vulnerabilities are often due to factors such as poor coding practices, misconfigurations, and an excessive dependence on third party libraries and not because the frameworks themselves contain security vulnerabilities. In this research paper, we discuss the most common types of attack vectors (XSS, CSRF, SQL/NoSQL injection, SSTI, and RCE) and supply chain threats found in package managers. We conclude that most security breaches occur as the result of developer error and not due to design flaws within the frameworks.},
keywords = {Web security, vulnerabilities, modern web frameworks, XSS, CSRF, API security, supply chain attacks},
month = {June},
}
Submit your research paper and those of your network (friends, colleagues, or peers) through your IPN account, and receive 800 INR for each paper that gets published.
Join NowNational Conference on Sustainable Engineering and Management - 2024 Last Date: 15th March 2024
Submit inquiry