16% of web vulnerabilities are still XSS
tinfoilsecurity.com
tinfoilsecurity.com
Web vulnerability scanners can diff a lot in their results. Crawling algos/site coverage, finding and using different input vectors, specific testing methods &c are all very different across various products. Sectoolmarket is a good resource with results from WIVET (crawl tests more or less) and WAVSEP (detecting vulnerabilities). Even so, those benchmarks only cover a very small portion of possible web application attack vectors. And let's not forget the problem of crawling "The Deep Web" i.e., stateful web applications.
TL;DR: title is wrong.