CWE-79: Improper Neutralization of Input During Web Page Generation
Cross-site Scripting is a software weakness pattern tracked by CWE 79. The local starter record is replaced by the official MITRE CWE import when the sync pipeline runs.
Search official CWE records, understand business impact, map weaknesses to CVEs and ATT&CK context, and turn recurring weakness patterns into concrete secure design decisions.
Reference Search
Use exact IDs such as CWE-79, search weakness names, or browse developer-focused filters.
High-Value Resources
Featured Weaknesses
Cross-site Scripting is a software weakness pattern tracked by CWE 79. The local starter record is replaced by the official MITRE CWE import when the sync pipeline runs.
SQL Injection is a software weakness pattern tracked by CWE 89. The local starter record is replaced by the official MITRE CWE import when the sync pipeline runs.
Out-of-bounds Write is a software weakness pattern tracked by CWE 787. The local starter record is replaced by the official MITRE CWE import when the sync pipeline runs.
OS Command Injection is a software weakness pattern tracked by CWE 78. The local starter record is replaced by the official MITRE CWE import when the sync pipeline runs.
Path Traversal is a software weakness pattern tracked by CWE 22. The local starter record is replaced by the official MITRE CWE import when the sync pipeline runs.
Cross-Site Request Forgery is a software weakness pattern tracked by CWE 352. The local starter record is replaced by the official MITRE CWE import when the sync pipeline runs.
Top List
Dictionary