r/websecurityresearch

11k members
r/websecurityresearch is a subreddit with 11k members. The most common kinds of discussions are solution requests and pain & anger, and the community frequently discusses security, web, xss, rce, and vulnerabilities.
A community for sharing and discussing novel web security research.

Popular Themes in r/websecurityresearch

#1
Solution Requests
: "GraphQL Security Testing Without a Schema"
12 posts
#2
Pain & Anger
: "Bypassing Firefox's HTML Sanitizer API"
8 posts
#3
Self-Promotion
: "of-CORS: a framework for hacking internal apps with open CORS via bug bounty"
5 posts
#4
Advice Requests
: "How to build custom scanners for web security research automation"
3 posts
#5
Ideas
: "New DOM Clobbering technique: blocking property assignments"
2 posts
#6
News
: "HTTP/1.1 must die: the desync endgame"
2 posts

Popular Topics in r/websecurityresearch

#1

Security

: "Unexpected Security footguns in Go's parsers"
60 posts
#2

Web

: "從 2013 到 2023: Web Security 十年之進化與趨勢! - From 2013 to 2023: Ten Years of Web Security Evolution and Trends!"
31 posts
#3

Xss

: "Hacking Swagger-UI - from Xss to account takeovers"
28 posts
#4

Rce

: "Escalating file write into Rce on Python"
28 posts
#5

Vulnerabilities

: "ParseThru: Exploiting HTTP Parameter Smuggling in Golang"
25 posts
#6

Exploiting

: "Bypassing WAFs with the phantom $Version cookie"
22 posts
#7

Exploit

: "Xalan-J: integer truncation in XSLTC - The Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the XSLTC compiler and execute arbitrary Java bytecode - SAML sig verif a vector"
17 posts
#8

Ssrf

: "NPM request Library Ssrf Cross Protocol Redirect Bypass"
16 posts
#9

Remote Code Execution

: "Unserializable, but unreachable: Remote Code Execution on vBulletin"
16 posts
#10

Exploit Development

: "Exploring the World of ESI Injection"
14 posts

Flair Used in r/websecurityresearch

#1
reject: not novel technique
: "GraphCrawler: GraphQL automated security testing toolkit"
1 post

Member Growth in r/websecurityresearch

Yearly
+1k members(12.5%)

Similar Subreddits to r/websecurityresearch

/r/blueteamsec

r/blueteamsec

71k members
26.3% / yr
/r/bugbounty

r/bugbounty

91k members
44.1% / yr

r/Infosec

38k members
28.7% / yr
/r/InfoSecNews

r/InfoSecNews

25k members
20.6% / yr
/r/InfoSecWriteups

r/InfoSecWriteups

3k members
88.6% / yr
/r/netsec

r/netsec

570k members
7.0% / yr
/r/SecOpsDaily

r/SecOpsDaily

13k members
606.6% / yr
/r/SecurityIntelligence

r/SecurityIntelligence

128 members
77.8% / yr

r/vrd

9k members
0.9% / yr

r/websec

8k members
2.0% / yr

About

GummySearch helps people research Reddit communities by organizing activity, growth, themes, and post-level signals into one place.

This page gives a focused view of r/websecurityresearch, including current member size, discussion patterns, product reviews, and related communities to explore.

This data is synced periodically so insights stay current and useful for ongoing research.

Last updated: August 9, 2026