logo

CISA Urges Software Makers to Eliminate XSS Flaws

ID: 979a1309-137f-590d-9235-4be36ce87393

STIX ID: report--979a1309-137f-590d-9235-4be36ce87393

Feed Name: Dark Reading

Threat Score
40/100

Date Published: 2024-09-17

Date Updated: 2026-04-21

Author: Edge Editors

...
...

CISA and the FBI issued a Secure by Design alert urging software makers to eliminate cross-site scripting (XSS) vulnerabilities prior to shipping products, noting XSS remains widespread and preventable. The alert recommends validating and sanitizing inputs, using modern web frameworks with proper output encoding, performing adversarial product testing, and adopting Secure by Design practices promoted by CISA, referencing prior alerts on common vulnerability classes and a vendor pledge to improve security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.