logo

CISA urges software devs to weed out XSS vulnerabilities

ID: 4fa07bdd-469b-5862-8403-a286d27f9c81

STIX ID: report--4fa07bdd-469b-5862-8403-a286d27f9c81

Feed Name: Bleeping Computer

Threat Score
50/100

Date Published: 2024-09-17

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA and the FBI warned technology manufacturers about persistent cross-site scripting (XSS) vulnerabilities, urging organizations to adopt secure-by-design practices, perform thorough input validation and output encoding, and conduct adversarial testing and code review to prevent XSS in future software releases. The alert highlights XSS’s high prevalence (ranking second in MITRE's top 25 weaknesses for 2021–2022) and situates this guidance within CISA’s broader Secure by Design series of advisories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.