MITRE: Cross-Site Scripting Is 2024’s Most Dangerous Software Weakness

Teilen:

In addition to XSS, MITRE and CISA’s 2024 list of the 25 most dangerous security vulnerability types (CWEs) also flagged out-of-bounds write, SQL injection, CSRF, and path traversal.

Although a new methodology shook up the rankings of this year’s most dangerous software bugs, the classic persistent threats still proved to be the biggest risk to organizations, reinforcing the need for continued focus on — and investment in — secure code.

The annual Common Weakness Enumeration (CWE) list is compiled by MITRE and the Cybersecurity and Infrastructure Agency (CISA). This year, for the first time, their formula included both severity and frequency of the flaws.

“Weaknesses that were rarely discovered will not receive a high frequency score, regardless of the typical consequence associated with any exploitation,” the list’s methodology page explained. “Weaknesses that are both common and caused significant harm will receive the highest scores.”

2024’s Most Dangerous Security Vulnerability Categories

The year’s top weaknesses, according to the 2024 CWE list, was cross-site scripting (second last year), followed by out-of-bounds write (2023’s winner), SQL injection (also third last year), cross-site request forgery (CSRF) (ninth in 2023), and path traversal (eighth last year).

“While we see a bit of movement in rankings throughout the list for sure, we also continue to see the presence of the ‘usual suspects’ (e.g., CWE-79, CWE-89, CWE-125),” says Alec Summers, the project leader for the CVE Program at MITRE and one of the list’s authors. “It’s an ongoing concern that these and other stubborn weaknesses remain high on the Top 25 consistently.”

The only real curveball in this year’s rankings, he points out, was CRSF rising from the ninth spot last year to fourth in 2024. “This might reflect a greater emphasis on CSRF by vulnerability researchers or maybe there are improvements in CSRF detection, or maybe more adversaries are focusing on this kind of issue. We can’t be completely sure why it jumped the way it did,” Summers says.

As the software development life cycle (SDLC) and software supply chain become more labyrinthine every year, and everyday software flaws continue to proliferate, it’s increasingly important for organizations get a handle on their systems before everyday weaknesses become something more sinister, he recommends.

“Looking at the Top 25, organizations are strongly encouraged to review and leverage the list as a guiding resource for shaping their software security strategies,” Summers says. “By prioritizing them in both development and procurement processes, organizations can more proactively address risk.”

Shoring Up the Software Supply Chain Starts at Home

Those efforts likewise should extend across the software supply chain, Summers adds.

“It’s becoming more and more important for organizations to adopt and demand their suppliers adopt root cause mapping CVE with CWE,” he urges. “This encourages a valuable feedback loop into an organization’s SDLC and architecture design planning, which in addition to increasing product security can also save money: The more weaknesses avoided in your product development, the less vulnerabilities to manage after deployment.”

In addition to incorporating a new methodology for determining which software flaws posed the most risk, 2024 was the first year the full community of CVE Numbering Authorities (CNAs) contributed to the CWE Program’s effort. In total 148 CNAs helped develop this year’s list, according to the CWE Project. Currently there are 421 CNAs across 40 countries, according to CVE.org.

Becky Bracken

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
9:09 am, Juli 13, 2025
Wetter-Symbol 20°C
L: 17° | H: 21°
klarer Himmel
Luftfeuchtigkeit: 71 %
Druck: 1014 mb
Wind: 4 mph NE
Windböe: 6 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 3%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:58 am
Sonnenuntergang: 9:13 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
17° | 21°°C 0 mm 0% 6 mph 71 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
19° | 27°°C 0 mm 0% 15 mph 71 % 1015 mb 0 mm/h
Di. Juli 15 10:00 pm
Wetter-Symbol
15° | 22°°C 1 mm 100% 17 mph 85 % 1016 mb 0 mm/h
Mi. Juli 16 10:00 pm
Wetter-Symbol
14° | 27°°C 0.11 mm 11% 11 mph 85 % 1017 mb 0 mm/h
Do. Juli 17 10:00 pm
Wetter-Symbol
18° | 27°°C 1 mm 100% 13 mph 95 % 1015 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
20° | 22°°C 0 mm 0% 4 mph 71 % 1013 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
22° | 27°°C 0 mm 0% 3 mph 62 % 1013 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
27° | 30°°C 0 mm 0% 0 mph 42 % 1011 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 6 mph 31 % 1008 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 6 mph 40 % 1010 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 5 mph 40 % 1011 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 5 mph 52 % 1010 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 9 mph 71 % 1011 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,953.28
0.17%
Ethereum(ETH)
€2,535.39
-0.08%
XRP(XRP)
€2.40
0.98%
Fesseln(USDT)
€0.86
-0.01%
Solana(SOL)
€139.11
-0.28%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.170593
-0.87%
Shiba Inu(SHIB)
€0.000011
-0.91%
Pepe(PEPE)
€0.000010
-1.28%
Peanut das Eichhörnchen(PNUT)
€0.246209
7.19%
Nach oben scrollen