The OWASP Web Security Testing Guide (WSTG) is the closest thing the industry has to a shared methodology for testing web applications. Its value is coverage: it stops a tester from spending three days on injection and never looking at session management.
How it is organised
Testing is grouped by area — information gathering, configuration, identity management, authentication, authorisation, session management, input validation, error handling, cryptography, business logic and client-side. Each area lists objectives and how to approach them.
Using it well
Work through the areas, but let the application decide the depth. A read-only marketing site deserves an hour on configuration; a multi-tenant billing system deserves days on authorisation and business logic.
The guide tells you what to look at, not what matters here. That judgement is the job.
Where findings actually come from
In practice most serious findings in modern applications cluster in three places: authorisation (one user reaching another's data), business logic (a legitimate sequence of requests producing an illegitimate outcome), and authentication flows (reset, enrolment, federation and session lifetime).
Framework defaults have largely removed the classic injection and output encoding issues from well-built applications; access control cannot be fixed by a framework default, because only the application knows who should see what.