CWE Top 25 Most Dangerous Software Weaknesses (2024)
CWE Top 25 2024: Injection and Input Handling

CWE Top 25 Most Dangerous Software Weaknesses (2024) CWE-79: Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

Rank 1 in the 2024 CWE Top 25 (frequency x severity of CVEs). Cross-site Scripting (XSS): the software does not neutralise user-controllable input before it is placed in output used as a web page, allowing attacker-supplied script to execute in victims' browsers.

Other controls in CWE Top 25 2024: Injection and Input Handling

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.