Veracode

30 STATS4 REPORTS

All Statistics

Over 85% of tasks related to Cryptographic Algorithms passed across the industry.

VeracodeOctober 2025 Update: GenAI Code Security Report·Nov 18, 2025
Gen AIGen AI code

OpenAI’s GPT-5 Mini achieved a 72% pass rate on security tests, marking the highest recorded to date.

VeracodeOctober 2025 Update: GenAI Code Security Report·Nov 18, 2025
Gen AIGen AI codeOpenAIGPT-5 Mini

OpenAI’s standard GPT-5 achieved a 70% pass rate on security tests.

VeracodeOctober 2025 Update: GenAI Code Security Report·Nov 18, 2025
Gen AIGen AI codeOpenAIGPT-5

The pass rates for Log Injection vulnerabilities were near 12% across all evaluated models.

VeracodeOctober 2025 Update: GenAI Code Security Report·Nov 18, 2025
Gen AIGen AI codeLog Injection vulnerabilities

Qwen3 Coder achieved a 50% pass rate on security tests.

VeracodeOctober 2025 Update: GenAI Code Security Report·Nov 18, 2025
Gen AIGen AI codeQwen3 Coder

Google Gemini 2.5 Pro achieved a 59% pass rate on security tests.

VeracodeOctober 2025 Update: GenAI Code Security Report·Nov 18, 2025
Gen AIGen AI codeGoogle GeminiGemini 2.5 Pro

Anthropic’s Claude Sonnet 4.5 achieved a 50% pass rate on security tests.

VeracodeOctober 2025 Update: GenAI Code Security Report·Nov 18, 2025
Gen AIGen AI codeAnthropicClaude Sonnet 4.5

The pass rates for Cross-Site Scripting (XSS) vulnerabilities remained below 14% across all evaluated models.

VeracodeOctober 2025 Update: GenAI Code Security Report·Nov 18, 2025
Gen AIGen AI codeXSS vulnerabilities

xAI Grok 4 achieved a 55% pass rate on security tests.

VeracodeOctober 2025 Update: GenAI Code Security Report·Nov 18, 2025
Gen AIGen AI codexAI Grok 4

OpenAI’s non-reasoning GPT-5-chat model delivered a 52% pass rate on security tests.

VeracodeOctober 2025 Update: GenAI Code Security Report·Nov 18, 2025
Gen AIGen AI codeOpenAIGPT-5

Open-source flaws account for over 82% of critical security debt at financial firms, despite third-party code representing only 17% of total security debt.

VeracodeState of Software Security·Oct 29, 2025
Open-source VulnerabilitiesVulnerabilitiesremediationsecurity debt

63% of banking, financial services, and insurance organizations reported harboring critical security debt in 2025, which is 13 percentage points higher than the cross-industry average.

VeracodeState of Software Security·Oct 29, 2025
Open-source VulnerabilitiesVulnerabilitiessecurity debt

Top-performing BFSI enterprises remediate over 9% of open flaws monthly, while lagging organizations have security debt in 85% or more of their applications.

VeracodeState of Software Security·Oct 29, 2025
Open-source VulnerabilitiesVulnerabilitiesremediation

77% of financial services organizations reported accruing some level of security debt.

VeracodeState of Software Security·Oct 29, 2025
Open-source VulnerabilitiesVulnerabilitiessecurity debt

The average flaw half-life for financial services organizations is 276 days, indicating it takes nearly a month longer to fix security issues than in other industries.

VeracodeState of Software Security·Oct 29, 2025
Open-source VulnerabilitiesVulnerabilities

LLMs failed to secure code against cross-site scripting (CWE-80) in 86% of cases.

Veracode2025 GenAI Code Security Report·Jul 30, 2025
AI codeGen AILLMsCross-site scriptin

AI-generated code introduces security vulnerabilities in 45% of cases.

Veracode2025 GenAI Code Security Report·Jul 30, 2025
AI codeGen AISecurity vulnerabilities

When given a choice between a secure and insecure method to write code, GenAI models chose the insecure option 45% of the time.

Veracode2025 GenAI Code Security Report·Jul 30, 2025
AI codeGen AISecurity vulnerabilities

In 45% of all test cases, LLMs introduced vulnerabilities classified within the OWASP Top 10.

Veracode2025 GenAI Code Security Report·Jul 30, 2025
AI codeGen AILLMsOWASP

Java was found to be the riskiest language for AI code generation, with a security failure rate over 70%. Other major languages, such as Python, C#, and JavaScript, presented significant risk, with failure rates between 38 percent and 45 percent.

Veracode2025 GenAI Code Security Report·Jul 30, 2025
AI codeGen AIJavaPythonC#

LLMs failed to secure code against log injection (CWE-117) in 88% of cases

Veracode2025 GenAI Code Security Report·Jul 30, 2025
AI codeGen AILLMsLog injection

Leading organisations keep open-source critical debt under 15 percent, while 100 percent of critical debt is open source in lagging organisations

VeracodeState of Software Security 2025·Feb 27, 2025

Less than 17 percent of applications in leading organisations carry security debt, compared with more than 67 percent in lagging ones.

VeracodeState of Software Security 2025·Feb 27, 2025

Top performers remediate half of flaws in five weeks; lower-performing organisations take longer than a year.

VeracodeState of Software Security 2025·Feb 27, 2025

70% of security debt stems from third-party code and the software supply chain.

VeracodeState of Software Security 2025·Feb 27, 2025

The average time to fix security flaws has increased from 171 days to 252 days over the past five years. This is an increase of 327 percent since the report’s first volume 15 years ago.

VeracodeState of Software Security 2025·Feb 27, 2025

50 percent of organisations now carry critical security debt, which is defined as flaws left open for longer than a year.

VeracodeState of Software Security 2025·Feb 27, 2025

The rate of applications passing the Open Worldwide Application Security Project (OWASP) Top 10 has increased by 63 percent over the past five years. It has more than doubled in 15 years.

VeracodeState of Software Security 2025·Feb 27, 2025

Leading organisations have flaws in fewer than 43 percent of applications, while lagging organisations exceed 86 percent.

VeracodeState of Software Security 2025·Feb 27, 2025

Leading organisations resolve over 10 percent of flaws monthly, whereas laggards address less than 1 percent.

VeracodeState of Software Security 2025·Feb 27, 2025