Skip to main content

CWEs that violate the OWASP 2025 standard

Important

These CWEs will be supported June 30, 2026.

The following table lists all the CWEs that might cause an application to not pass a policy that includes an Auto-Update OWASP policy rule.

CWE IDCWE nameStatic supportDynamic supportVeracode severityOn OWASP 2021 list
15External Control of System or Configuration SettingX4 - HighX
22Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)XX3 - MediumX
73External Control of File Name or PathX3 - MediumX
74Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)X4 - HighX
77Improper Neutralization of Special Elements used in a Command (Command Injection)X5 - Very High (Critical)X
78Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)XX5 - Very High (Critical)X
79Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)XX3 - MediumX
80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)XX3 - MediumX
83Improper Neutralization of Script in Attributes in a Web PageX3 - MediumX
86Improper Neutralization of Invalid Characters in Identifiers in Web PagesX3 - MediumX
88Argument Injection or ModificationX3 - MediumX
89Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)XX4 - HighX
90Improper Neutralization of Special Elements used in an LDAP Query (LDAP Injection)X3 - MediumX
91XML Injection (Blind XPath Injection)XX3 - MediumX
93Improper Neutralization of CRLF Sequences (CRLF Injection)X3 - MediumX
94Improper Control of Generation of CodeX3 - MediumX
95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')XX5 - Very High (Critical)X
98Improper Control of Filename for Include/Require Statement in PHP Program (PHP File Inclusion)XX4 - HighX
99Improper Control of Resource IdentifiersX3 - MediumX
103Struts: Incomplete validate() Method DefinitionX3 - Medium
104Struts: Form Bean Does Not Extend Validation ClassX3 - Medium
112Missing XML ValidationX3 - MediumX
113Improper Neutralization of CRLF Sequences in HTTP Headers (HTTP Response Splitting)XX3 - MediumX
114Process ControlX5 - Very High (Critical)X
115Misinterpretation of InputX4 - High
117Improper Output Neutralization for LogsX3 - MediumX
129Improper Validation of Array IndexX3 - MediumX
134Use of Externally-Controlled Format StringX5 - Very High (Critical)X
183Permissive List of Allowed InputsX3 - MediumX
200Information ExposureXX2 - LowX
201Insertion of Sensitive Information Into Sent DataX2 - LowX
209Information Exposure Through an Error MessageXX2 - LowX
215Information Exposure Through Debug InformationXX2 - LowX
223Omission of Security-relevant InformationX2 - LowX
234Failure to Handle Missing ParameterX3 - Medium
248Uncaught ExceptionX2 - Low
252Unchecked Return ValueX2 - Low
256Plaintext Storage of a PasswordX3 - MediumX
258Empty Password in Configuration FileX3 - Medium
259Use of Hard-coded PasswordXX3 - MediumX
261Weak Cryptography for PasswordsX3 - MediumX
272Least Privilege ViolationX3 - MediumX
273Improper Check for Dropped PrivilegesX3 - Medium
282Improper Ownership ManagementX3 - MediumX
284Improper Access ControlX3 - Medium
285Improper AuthorizationX3 - MediumX
287Improper AuthenticationXX4 - HighX
295Improper Certificate ValidationX3 - MediumX
296Improper Following of Chain of Trust for Certificate ValidationX3 - MediumX
297Improper Validation of Host-specific Certificate DataXX3 - MediumX
298Improper Validation of Certificate ExpirationX3 - MediumX
299Improper Check for Certificate RevocationX3 - MediumX
311Missing Encryption of Sensitive DataX3 - MediumX
312Cleartext Storage of Sensitive InformationX3 - MediumX
313Plaintext Storage in a File or on DiskX3 - MediumX
316Plaintext Storage in MemoryX3 - MediumX
319Cleartext Transmission of Sensitive InformationX3 - MediumX
321Use of Hard-coded Cryptographic KeyXX3 - MediumX
325Missing Cryptographic StepX3 - Medium
326Inadequate Encryption StrengthXX3 - MediumX
327Use of a Broken or Risky Cryptographic AlgorithmXX3 - MediumX
329Not Using a Random IV with CBC ModeX2 - LowX
330Use of Insufficiently Random ValuesX3 - MediumX
331Insufficient EntropyX3 - MediumX
338Use of Cryptographically Weak Pseudo-Random Number GeneratorX3 - MediumX
345Insufficient Verification of Data AuthenticityXX4 - HighX
346Origin Validation ErrorX3 - MediumX
347Improper Verification of Cryptographic SignatureX2 - LowX
350Reliance on Reverse DNS Resolution for a Security-Critical ActionX3 - MediumX
352Cross-Site Request Forgery (CSRF)XX3 - MediumX
354Improper Validation of Integrity Check ValueX3 - MediumX
359Exposure of Private Information (Privacy Violation)XX2 - LowX
366Race Condition within a ThreadX3 - Medium
367Time-of-check Time-of-use (TOCTOU) Race ConditionX3 - Medium
377Insecure Temporary FileX3 - MediumX
382J2EE Bad Practices: Use of System.exit()X2 - Low
384Session FixationXX3 - MediumX
402Transmission of Private Resources into a New Sphere (Resource Leak)X3 - MediumX
421Race Condition During Access to Alternate ChannelX3 - MediumX
426Untrusted Search PathX3 - MediumX
427Uncontrolled Search Path ElementX3 - MediumX
434Unrestricted Upload of File with Dangerous TypeX4 - HighX
441Unintended Proxy or Intermediary (Confused Deputy)X3 - MediumX
451User Interface (UI) Misrepresentation of Critical InformationX3 - Medium
470Use of Externally-Controlled Input to Select Classes or Code (Unsafe Reflection)X3 - MediumX
472External Control of Assumed-Immutable Web ParameterX3 - MediumX
479Signal Handler Use of a Non-Reentrant FunctionX3 - Medium
489Leftover Debug CodeX3 - Medium
497Exposure of System Data to an Unauthorized Control SphereX2 - LowX
502Deserialization of Untrusted DataXX3 - MediumX
506Embedded Malicious CodeX4 - High
511Logic/Time BombX5 - Very High (Critical)
522Insufficiently Protected CredentialsXX3 - MediumX
526Information Exposure Through Environmental VariablesX2 - LowX
530Exposure of Backup File to an Unauthorized Control SphereX2 - LowX
532Insertion of Sensitive Information into Log FileX2 - LowX
538File and Directory Information ExposureX2 - LowX
547Use of Hard-coded, Security-relevant ConstantsX3 - MediumX
548Information Exposure Through Directory ListingX2 - LowX
560Use of Umask() with Chmod-Style ArgumentX3 - Medium
564SQL Injection: HibernateX4 - HighX
566Authorization Bypass Through User-Controlled SQL Primary KeyX3 - MediumX
601URL Redirection to Untrusted Site (Open Redirect)XX3 - MediumX
611Information Exposure Through XML External Entity ReferenceXX3 - MediumX
614Sensitive Cookie in HTTPS Session Without Secure AttributeXX2 - LowX
615Information Exposure Through CommentsX2 - LowX
618Exposed Unsafe ActiveX MethodX5 - Very High (Critical)
628Function Call with Incorrectly Specified ArgumentsX2 - Low
639Authorization Bypass Through User-Controlled KeyX4 - HighX
642External Control of Critical State DataX2 - LowX
668Exposure of Resource to Wrong SphereXX3 - MediumX
676Use of Potentially Dangerous FunctionX3 - Medium
693Protection Mechanism FailureXX3 - Medium
708Incorrect Ownership AssignmentX4 - HighX
732Incorrect Permission Assignment for Critical ResourceX3 - MediumX
749Exposed Dangerous Method or FunctionX4 - High
757Selection of Less-Secure Algorithm During Negotiation (Algorithm Downgrade)XX3 - MediumX
760Use of a One-Way Hash with a Predictable SaltX3 - MediumX
780Use of RSA without Optimal Asymmetric Encryption PaddingX3 - MediumX
798Use of Hard-code CredentialsX3 - MediumX
829Inclusion of Functionality from Untrusted Control SphereXX3 - MediumX
830Inclusion of Web Functionality from an Untrusted SourceX2 - LowX
862Missing AuthorizationX2 - Low
915Improperly Controlled Modification of Dynamically-Determined Object AttributesX3 - MediumX
916Use of Password Hash With Insufficient Computational EffortX3 - MediumX
918Server-side Request ForgeryXX3 - MediumX
923Improper Restriction of Communication Channel to Intended EndpointsX3 - Medium
926Improper Export of Android Application ComponentsX3 - MediumX
942Permissive Cross-domain Policy with Untrusted DomainsX3 - MediumX
943Improper Neutralization of Special Elements in Data Query LogicXX4 - HighX
1174ASP.NET Misconfiguration: Improper Model ValidationX2 - LowX
1236Improper Neutralization of Formula Elements in a CSV FileX3 - MediumX
1336Improper Neutralization of Special Elements Used in a Template EngineX5 - Very High (Critical)
1427Improper Neutralization of Input Used for LLM PromptingX4 - High