This paper proposes a novel methodology for quantifying vulnerabilities in web applications using a combination of fuzzy logic and the analytic hierarchy process (AHP). It applies the goal question metrics (GQM) framework to identify security factors within the context of the Department of Transportation as a proof of concept. The research aims to enhance understanding of web application vulnerabilities and provide a structured measurement approach to improve cybersecurity practices.