logo

MITRE: Cross-Site Scripting Is 2024's Most Dangerous Software Weakness

ID: f0458854-50dc-565b-a9a7-0b16784948b2

STIX ID: report--f0458854-50dc-565b-a9a7-0b16784948b2

Feed Name: Dark Reading

Threat Score
20/100

Date Published: 2024-11-21

Date Updated: 2026-04-21

Author: Becky Bracken, Senior Editor, Dark Reading

...
...

The article summarizes the 2024 CWE Top 25 list (compiled by MITRE and CISA), which for the first time weighted both severity and frequency; it highlights top weakness categories such as cross-site scripting, out-of-bounds write, SQL injection, CSRF, and path traversal, notes the involvement of CNAs in producing the list, and urges organizations to prioritize CWE mapping, secure SDLC practices, and supply-chain security to reduce persistent software weaknesses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.