MITRE: Cross-Site Scripting Is 2024’s Most Dangerous Software Weakness

Share:

In addition to XSS, MITRE and CISA’s 2024 list of the 25 most dangerous security vulnerability types (CWEs) also flagged out-of-bounds write, SQL injection, CSRF, and path traversal.

Although a new methodology shook up the rankings of this year’s most dangerous software bugs, the classic persistent threats still proved to be the biggest risk to organizations, reinforcing the need for continued focus on — and investment in — secure code.

The annual Common Weakness Enumeration (CWE) list is compiled by MITRE and the Cybersecurity and Infrastructure Agency (CISA). This year, for the first time, their formula included both severity and frequency of the flaws.

“Weaknesses that were rarely discovered will not receive a high frequency score, regardless of the typical consequence associated with any exploitation,” the list’s methodology page explained. “Weaknesses that are both common and caused significant harm will receive the highest scores.”

2024’s Most Dangerous Security Vulnerability Categories

The year’s top weaknesses, according to the 2024 CWE list, was cross-site scripting (second last year), followed by out-of-bounds write (2023’s winner), SQL injection (also third last year), cross-site request forgery (CSRF) (ninth in 2023), and path traversal (eighth last year).

“While we see a bit of movement in rankings throughout the list for sure, we also continue to see the presence of the ‘usual suspects’ (e.g., CWE-79, CWE-89, CWE-125),” says Alec Summers, the project leader for the CVE Program at MITRE and one of the list’s authors. “It’s an ongoing concern that these and other stubborn weaknesses remain high on the Top 25 consistently.”

The only real curveball in this year’s rankings, he points out, was CRSF rising from the ninth spot last year to fourth in 2024. “This might reflect a greater emphasis on CSRF by vulnerability researchers or maybe there are improvements in CSRF detection, or maybe more adversaries are focusing on this kind of issue. We can’t be completely sure why it jumped the way it did,” Summers says.

As the software development life cycle (SDLC) and software supply chain become more labyrinthine every year, and everyday software flaws continue to proliferate, it’s increasingly important for organizations get a handle on their systems before everyday weaknesses become something more sinister, he recommends.

“Looking at the Top 25, organizations are strongly encouraged to review and leverage the list as a guiding resource for shaping their software security strategies,” Summers says. “By prioritizing them in both development and procurement processes, organizations can more proactively address risk.”

Shoring Up the Software Supply Chain Starts at Home

Those efforts likewise should extend across the software supply chain, Summers adds.

“It’s becoming more and more important for organizations to adopt and demand their suppliers adopt root cause mapping CVE with CWE,” he urges. “This encourages a valuable feedback loop into an organization’s SDLC and architecture design planning, which in addition to increasing product security can also save money: The more weaknesses avoided in your product development, the less vulnerabilities to manage after deployment.”

In addition to incorporating a new methodology for determining which software flaws posed the most risk, 2024 was the first year the full community of CVE Numbering Authorities (CNAs) contributed to the CWE Program’s effort. In total 148 CNAs helped develop this year’s list, according to the CWE Project. Currently there are 421 CNAs across 40 countries, according to CVE.org.

Becky Bracken

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
5:33 am, Jun 28, 2025
weather icon 19°C
L: 18° | H: 20°
broken clouds
Humidity: 85 %
Pressure: 1022 mb
Wind: 10 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:45 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
18° | 20°°C 0 mm 0% 11 mph 85 % 1025 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 31°°C 0 mm 0% 7 mph 79 % 1025 mb 0 mm/h
Mon Jun 30 10:00 pm
weather icon
21° | 35°°C 0.2 mm 20% 9 mph 69 % 1021 mb 0 mm/h
Tue Jul 01 10:00 pm
weather icon
22° | 32°°C 0 mm 0% 10 mph 70 % 1017 mb 0 mm/h
Wed Jul 02 10:00 pm
weather icon
20° | 28°°C 0.85 mm 85% 14 mph 69 % 1018 mb 0 mm/h
Today 7:00 am
weather icon
19° | 20°°C 0 mm 0% 9 mph 85 % 1022 mb 0 mm/h
Today 10:00 am
weather icon
21° | 23°°C 0 mm 0% 10 mph 81 % 1023 mb 0 mm/h
Today 1:00 pm
weather icon
24° | 27°°C 0 mm 0% 11 mph 65 % 1023 mb 0 mm/h
Today 4:00 pm
weather icon
26° | 26°°C 0 mm 0% 10 mph 50 % 1023 mb 0 mm/h
Today 7:00 pm
weather icon
27° | 27°°C 0 mm 0% 9 mph 57 % 1023 mb 0 mm/h
Today 10:00 pm
weather icon
23° | 23°°C 0 mm 0% 8 mph 66 % 1025 mb 0 mm/h
Tomorrow 1:00 am
weather icon
20° | 20°°C 0 mm 0% 7 mph 69 % 1025 mb 0 mm/h
Tomorrow 4:00 am
weather icon
18° | 18°°C 0 mm 0% 5 mph 79 % 1025 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,507.41
-0.18%
Ethereum(ETH)
€2,064.91
-1.13%
Tether(USDT)
€0.85
0.00%
XRP(XRP)
€1.86
3.78%
Solana(SOL)
€122.25
1.48%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.138251
0.04%
Shiba Inu(SHIB)
€0.000009
0.38%
Pepe(PEPE)
€0.000008
-0.50%
Scroll to Top