MITRE: Cross-Site Scripting Is 2024’s Most Dangerous Software Weakness

Teilen:

In addition to XSS, MITRE and CISA’s 2024 list of the 25 most dangerous security vulnerability types (CWEs) also flagged out-of-bounds write, SQL injection, CSRF, and path traversal.

Although a new methodology shook up the rankings of this year’s most dangerous software bugs, the classic persistent threats still proved to be the biggest risk to organizations, reinforcing the need for continued focus on — and investment in — secure code.

The annual Common Weakness Enumeration (CWE) list is compiled by MITRE and the Cybersecurity and Infrastructure Agency (CISA). This year, for the first time, their formula included both severity and frequency of the flaws.

“Weaknesses that were rarely discovered will not receive a high frequency score, regardless of the typical consequence associated with any exploitation,” the list’s methodology page explained. “Weaknesses that are both common and caused significant harm will receive the highest scores.”

2024’s Most Dangerous Security Vulnerability Categories

The year’s top weaknesses, according to the 2024 CWE list, was cross-site scripting (second last year), followed by out-of-bounds write (2023’s winner), SQL injection (also third last year), cross-site request forgery (CSRF) (ninth in 2023), and path traversal (eighth last year).

“While we see a bit of movement in rankings throughout the list for sure, we also continue to see the presence of the ‘usual suspects’ (e.g., CWE-79, CWE-89, CWE-125),” says Alec Summers, the project leader for the CVE Program at MITRE and one of the list’s authors. “It’s an ongoing concern that these and other stubborn weaknesses remain high on the Top 25 consistently.”

The only real curveball in this year’s rankings, he points out, was CRSF rising from the ninth spot last year to fourth in 2024. “This might reflect a greater emphasis on CSRF by vulnerability researchers or maybe there are improvements in CSRF detection, or maybe more adversaries are focusing on this kind of issue. We can’t be completely sure why it jumped the way it did,” Summers says.

As the software development life cycle (SDLC) and software supply chain become more labyrinthine every year, and everyday software flaws continue to proliferate, it’s increasingly important for organizations get a handle on their systems before everyday weaknesses become something more sinister, he recommends.

“Looking at the Top 25, organizations are strongly encouraged to review and leverage the list as a guiding resource for shaping their software security strategies,” Summers says. “By prioritizing them in both development and procurement processes, organizations can more proactively address risk.”

Shoring Up the Software Supply Chain Starts at Home

Those efforts likewise should extend across the software supply chain, Summers adds.

“It’s becoming more and more important for organizations to adopt and demand their suppliers adopt root cause mapping CVE with CWE,” he urges. “This encourages a valuable feedback loop into an organization’s SDLC and architecture design planning, which in addition to increasing product security can also save money: The more weaknesses avoided in your product development, the less vulnerabilities to manage after deployment.”

In addition to incorporating a new methodology for determining which software flaws posed the most risk, 2024 was the first year the full community of CVE Numbering Authorities (CNAs) contributed to the CWE Program’s effort. In total 148 CNAs helped develop this year’s list, according to the CWE Project. Currently there are 421 CNAs across 40 countries, according to CVE.org.

Becky Bracken

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:56 am, Juni 28, 2025
Wetter-Symbol 19°C
L: 18° | H: 20°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 84 %
Druck: 1022 mb
Wind: 10 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 40%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:45 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
18° | 20°°C 0 mm 0% 11 mph 84 % 1025 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 31°°C 0 mm 0% 7 mph 79 % 1025 mb 0 mm/h
Mo. Juni 30 10:00 pm
Wetter-Symbol
21° | 35°°C 0.2 mm 20% 9 mph 69 % 1021 mb 0 mm/h
Di. Juli 01 10:00 pm
Wetter-Symbol
22° | 32°°C 0 mm 0% 10 mph 70 % 1017 mb 0 mm/h
Mi. Juli 02 10:00 pm
Wetter-Symbol
20° | 28°°C 0.85 mm 85% 14 mph 69 % 1018 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 10 mph 84 % 1022 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
19° | 20°°C 0 mm 0% 9 mph 84 % 1022 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
22° | 24°°C 0 mm 0% 10 mph 76 % 1023 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 11 mph 55 % 1024 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 10 mph 50 % 1023 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 9 mph 57 % 1023 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 8 mph 66 % 1025 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 7 mph 69 % 1025 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,423.79
-0.14%
Ethereum(ETH)
€2,065.22
-0.73%
Fesseln(USDT)
€0.85
0.01%
XRP(XRP)
€1.86
3.52%
Solana(SOL)
€122.14
1.69%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.138220
-0.31%
Shiba Inu(SHIB)
€0.000009
0.52%
Pepe(PEPE)
€0.000008
-0.77%
Nach oben scrollen