The most common vulnerabilities in production applications are not sophisticated attacks. They are elementary attacks against systems that did not validate their inputs.
The complete validation discipline: validate everything from outside the system — HTTP parameters, headers, cookies, webhook payloads, file uploads, API responses from third parties.
Validate type, range, format, and length. Sanitise separately from validate. Validation rejects bad input. Sanitisation transforms acceptable input into a safe form for its destination.
The OWASP Top 10 has looked essentially the same for 15 years. The vulnerabilities are not new. The discipline to prevent them is apparently still not universal.
— Dick Bassey | DevDick | 2021