Skip to main content

CWEs that violate the OWASP standard

The following table lists the CWEs that violate the OWASP Top 10 standard. Only the supported CWEs on the most recent list will cause an application to fail a policy that includes the Auto-Update OWASP policy rule.

CWE IDCWE nameSAST supportDAST supportVeracode severityYears on list
15External Control of System or Configuration SettingYesNo4 - High2021, 2025
22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')YesYes3 - Medium2017, 2021, 2025
73External Control of File Name or PathYesNo3 - Medium2021, 2025
74Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')NoYes4 - High2017, 2021, 2025
77Improper Neutralization of Special Elements used in a Command ('Command Injection')YesNo5 - Very High (Critical)2017, 2021, 2025
78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')YesYes5 - Very High (Critical)2017, 2021, 2025
79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')YesYes3 - Medium2017, 2021, 2025
80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)YesYes3 - Medium2017, 2021, 2025
83Improper Neutralization of Script in Attributes in a Web PageNoYes3 - Medium2017, 2021, 2025
86Improper Neutralization of Invalid Characters in Identifiers in Web PagesYesNo3 - Medium2017, 2021, 2025
88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')YesNo3 - Medium2017, 2021, 2025
89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')YesYes4 - High2017, 2021, 2025
90Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')YesNo3 - Medium2017, 2021, 2025
91XML Injection (aka Blind XPath Injection)YesYes3 - Medium2017, 2021, 2025
93Improper Neutralization of CRLF Sequences ('CRLF Injection')YesNo3 - Medium2017, 2021, 2025
94Improper Control of Generation of Code ('Code Injection')YesNo3 - Medium2017, 2021, 2025
95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')YesYes5 - Very High (Critical)2017, 2021, 2025
98Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')YesYes4 - High2017, 2021, 2025
99Improper Control of Resource Identifiers ('Resource Injection')YesNo3 - Medium2017, 2021, 2025
103Struts: Incomplete validate() Method DefinitionYesNo3 - Medium2025
104Struts: Form Bean Does Not Extend Validation ClassYesNo3 - Medium2025
112Missing XML ValidationYesNo3 - Medium2021, 2025
113Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')YesYes3 - Medium2017, 2021, 2025
114Process ControlYesNo5 - Very High (Critical)2021, 2025
115Misinterpretation of InputNoYes4 - High2025
117Improper Output Neutralization for LogsYesNo3 - Medium2017, 2021, 2025
129Improper Validation of Array IndexYesNo3 - Medium2021, 2025
134Use of Externally-Controlled Format StringYesNo5 - Very High (Critical)2021, 2025
183Permissive List of Allowed InputsYesNo3 - Medium2021, 2025
200Exposure of Sensitive Information to an Unauthorized ActorYesYes2 - Low2021, 2025
201Insertion of Sensitive Information Into Sent DataYesNo2 - Low2021, 2025
209Generation of Error Message Containing Sensitive InformationYesYes2 - Low2017, 2021, 2025
215Insertion of Sensitive Information Into Debugging CodeYesYes2 - Low2021, 2025
223Omission of Security-relevant InformationYesNo2 - Low2017, 2021, 2025
234Failure to Handle Missing ParameterYesNo3 - Medium2025
248Uncaught ExceptionYesNo2 - Low2025
252Unchecked Return ValueYesNo2 - Low2025
256Plaintext Storage of a PasswordYesNo3 - Medium2017, 2021, 2025
258Empty Password in Configuration FileYesNo3 - Medium2017, 2021, 2025
259Use of Hard-coded PasswordYesYes3 - Medium2017, 2021, 2025
261Weak Encoding for PasswordYesNo3 - Medium2017, 2021, 2025
272Least Privilege ViolationYesNo3 - Medium2017, 2021, 2025
273Improper Check for Dropped PrivilegesYesNo3 - Medium2025
282Improper Ownership ManagementYesNo3 - Medium2017, 2021, 2025
284Improper Access ControlYesNo3 - Medium2017, 2021, 2025
285Improper AuthorizationYesNo3 - Medium2017, 2021, 2025
287Improper AuthenticationYesYes4 - High2017, 2021, 2025
295Improper Certificate ValidationYesNo3 - Medium2017, 2021, 2025
296Improper Following of a Certificate's Chain of TrustNoYes3 - Medium2017, 2021, 2025
297Improper Validation of Certificate with Host MismatchYesYes3 - Medium2017, 2021, 2025
298Improper Validation of Certificate ExpirationNoYes3 - Medium2017, 2021, 2025
299Improper Check for Certificate RevocationNoYes3 - Medium2017, 2021, 2025
311Missing Encryption of Sensitive DataYesNo3 - Medium2017, 2021, 2025
312Cleartext Storage of Sensitive InformationYesNo3 - Medium2017, 2021, 2025
313Cleartext Storage in a File or on DiskYesNo3 - Medium2017, 2021, 2025
316Cleartext Storage of Sensitive Information in MemoryYesNo3 - Medium2017, 2021, 2025
319Cleartext Transmission of Sensitive InformationYesNo3 - Medium2017, 2021, 2025
321Use of Hard-coded Cryptographic KeyYesYes3 - Medium2017, 2021, 2025
323Reusing a Nonce, Key Pair in EncryptionYesNo3 - Medium2021, 2025
325Missing Cryptographic StepNoYes3 - Medium2017, 2021, 2025
326Inadequate Encryption StrengthYesYes3 - Medium2017, 2021, 2025
327Use of a Broken or Risky Cryptographic AlgorithmYesYes3 - Medium2017, 2021, 2025
329Generation of Predictable IV with CBC ModeYesNo2 - Low2021, 2025
330Use of Insufficiently Random ValuesYesNo3 - Medium2021, 2025
331Insufficient EntropyYesNo3 - Medium2021, 2025
338Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)YesNo3 - Medium2021, 2025
345Insufficient Verification of Data AuthenticityYesYes4 - High2021, 2025
346Origin Validation ErrorYesNo3 - Medium2021, 2025
347Improper Verification of Cryptographic SignatureYesNo2 - Low2021, 2025
350Reliance on Reverse DNS Resolution for a Security-Critical ActionYesNo3 - Medium2017, 2021, 2025
352Cross-Site Request Forgery (CSRF)YesYes3 - Medium2021, 2025
354Improper Validation of Integrity Check ValueYesNo3 - Medium2021, 2025
359Exposure of Private Personal Information to an Unauthorized ActorYesYes2 - Low2017, 2021, 2025
366Race Condition within a ThreadYesNo3 - Medium2025
367Time-of-check Time-of-use (TOCTOU) Race ConditionYesNo3 - Medium2025
377Insecure Temporary FileYesNo3 - Medium2021, 2025
382J2EE Bad Practices: Use of System.exit()YesNo2 - Low2025
384Session FixationYesYes3 - Medium2017, 2021, 2025
402Transmission of Private Resources into a New Sphere ('Resource Leak')NoYes3 - Medium2021, 2025
421Race Condition During Access to Alternate ChannelYesNo3 - Medium2017, 2021, 2025
426Untrusted Search PathYesNo3 - Medium2021, 2025
427Uncontrolled Search Path ElementYesNo3 - Medium2021, 2025
434Unrestricted Upload of File with Dangerous TypeNoYes4 - High2021, 2025
441Unintended Proxy or Intermediary ('Confused Deputy')YesNo3 - Medium2021, 2025
451User Interface (UI) Misrepresentation of Critical InformationYesNo3 - Medium2021, 2025
470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')YesNo3 - Medium2021, 2025
472External Control of Assumed-Immutable Web ParameterYesNo3 - Medium2021, 2025
479Signal Handler Use of a Non-reentrant FunctionYesNo3 - Medium2025
489Active Debug CodeYesNo3 - Medium2025
497Exposure of Sensitive System Information to an Unauthorized Control SphereYesNo2 - Low2021, 2025
502Deserialization of Untrusted DataYesYes3 - Medium2017, 2021, 2025
506Embedded Malicious CodeYesNo4 - High2025
511Logic/Time BombYesNo5 - Very High (Critical)2025
522Insufficiently Protected CredentialsYesYes3 - Medium2017, 2021, 2025
526Cleartext Storage of Sensitive Information in an Environment VariableNoYes2 - Low2017, 2021, 2025
530Exposure of Backup File to an Unauthorized Control SphereNoYes2 - Low2021, 2025
532Insertion of Sensitive Information into Log FileYesNo2 - Low2021, 2025
538Insertion of Sensitive Information into Externally-Accessible File or DirectoryNoYes2 - Low2021, 2025
547Use of Hard-coded, Security-relevant ConstantsYesNo3 - Medium2021, 2025
548Exposure of Information Through Directory ListingNoYes2 - Low2017, 2021, 2025
564SQL Injection: HibernateYesNo4 - High2017, 2021, 2025
566Authorization Bypass Through User-Controlled SQL Primary KeyYesNo3 - Medium2017, 2021, 2025
601URL Redirection to Untrusted Site ('Open Redirect')YesYes3 - Medium2021, 2025
611Improper Restriction of XML External Entity ReferenceYesYes3 - Medium2017, 2021, 2025
614Sensitive Cookie in HTTPS Session Without 'Secure' AttributeYesYes2 - Low2017, 2021, 2025
615Inclusion of Sensitive Information in Source Code CommentsYesNo2 - Low2021, 2025
618Exposed Unsafe ActiveX MethodYesNo5 - Very High (Critical)2017, 2021, 2025
628Function Call with Incorrectly Specified ArgumentsYesNo2 - Low2025
639Authorization Bypass Through User-Controlled KeyYesNo4 - High2017, 2021, 2025
642External Control of Critical State DataNoYes2 - Low2021, 2025
668Exposure of Resource to Wrong SphereYesYes3 - Medium2021, 2025
676Use of Potentially Dangerous FunctionYesNo3 - Medium2025
693Protection Mechanism FailureYesYes3 - Medium2025
708Incorrect Ownership AssignmentYesNo4 - High2017, 2021, 2025
732Incorrect Permission Assignment for Critical ResourceYesNo3 - Medium2017, 2021, 2025
749Exposed Dangerous Method or FunctionYesNo4 - High2017, 2021, 2025
757Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')YesYes3 - Medium2021, 2025
760Use of a One-Way Hash with a Predictable SaltYesNo3 - Medium2017, 2021, 2025
780Use of RSA Algorithm without OAEPYesNo3 - Medium2017, 2021, 2025
798Use of Hard-coded CredentialsYesNo3 - Medium2017, 2021, 2025
829Inclusion of Functionality from Untrusted Control SphereYesYes3 - Medium2021, 2025
830Inclusion of Web Functionality from an Untrusted SourceNoYes2 - Low2021, 2025
862Missing AuthorizationNoYes2 - Low2017, 2021, 2025
915Improperly Controlled Modification of Dynamically-Determined Object AttributesYesNo3 - Medium2021, 2025
916Use of Password Hash With Insufficient Computational EffortYesNo3 - Medium2017, 2021, 2025
918Server-Side Request Forgery (SSRF)YesYes3 - Medium2021, 2025
923Improper Restriction of Communication Channel to Intended EndpointsYesNo3 - Medium2017, 2021, 2025
926Improper Export of Android Application ComponentsYesNo3 - Medium2017, 2021, 2025
942Permissive Cross-domain Security Policy with Untrusted DomainsYesNo3 - Medium2017, 2021, 2025
943Improper Neutralization of Special Elements in Data Query LogicYesYes4 - High2017, 2021, 2025
1174ASP.NET Misconfiguration: Improper Model ValidationYesNo2 - Low2021, 2025
1236Improper Neutralization of Formula Elements in a CSV FileYesNo3 - Medium2017, 2021, 2025
1336Improper Neutralization of Special Elements Used in a Template EngineYesNo5 - Very High (Critical)2017, 2021, 2025
1427Improper Neutralization of Input Used for LLM PromptingYesNo4 - High2017, 2021, 2025