Skip to main content

CWEs that violate the OWASP standard

Important

Support for the 2025 version will begin on June 30, 2026.

The following table lists the CWEs that violate the OWASP Top 10 standard. Only the supported CWEs on the most recent list will cause an application to fail a policy that includes the Auto-Update OWASP policy rule.

CWE IDCWE nameStatic supportDynamic supportVeracode severityYears on list
15External Control of System or Configuration SettingX4 - High2021, 2025
22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')XX3 - Medium2017, 2021, 2025
73External Control of File Name or PathX3 - Medium2021, 2025
74Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')X4 - High2017, 2021, 2025
77Improper Neutralization of Special Elements used in a Command ('Command Injection')X5 - Very High (Critical)2017, 2021, 2025
78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')XX5 - Very High (Critical)2017, 2021, 2025
79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')XX3 - Medium2017, 2021, 2025
80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)XX3 - Medium2017, 2021, 2025
83Improper Neutralization of Script in Attributes in a Web PageX3 - Medium2017, 2021, 2025
86Improper Neutralization of Invalid Characters in Identifiers in Web PagesX3 - Medium2017, 2021, 2025
88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')X3 - Medium2017, 2021, 2025
89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')XX4 - High2017, 2021, 2025
90Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')X3 - Medium2017, 2021, 2025
91XML Injection (aka Blind XPath Injection)XX3 - Medium2017, 2021, 2025
93Improper Neutralization of CRLF Sequences ('CRLF Injection')X3 - Medium2017, 2021, 2025
94Improper Control of Generation of Code ('Code Injection')X3 - Medium2017, 2021, 2025
95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')XX5 - Very High (Critical)2017, 2021, 2025
98Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')XX4 - High2017, 2021, 2025
99Improper Control of Resource Identifiers ('Resource Injection')X3 - Medium2017, 2021, 2025
103Struts: Incomplete validate() Method DefinitionX3 - Medium2025
104Struts: Form Bean Does Not Extend Validation ClassX3 - Medium2025
112Missing XML ValidationX3 - Medium2021, 2025
113Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')XX3 - Medium2017, 2021, 2025
114Process ControlX5 - Very High (Critical)2021, 2025
115Misinterpretation of InputX4 - High2025
117Improper Output Neutralization for LogsX3 - Medium2017, 2021, 2025
129Improper Validation of Array IndexX3 - Medium2021, 2025
134Use of Externally-Controlled Format StringX5 - Very High (Critical)2021, 2025
183Permissive List of Allowed InputsX3 - Medium2021, 2025
200Exposure of Sensitive Information to an Unauthorized ActorXX2 - Low2021, 2025
201Insertion of Sensitive Information Into Sent DataX2 - Low2021, 2025
209Generation of Error Message Containing Sensitive InformationXX2 - Low2017, 2021, 2025
215Insertion of Sensitive Information Into Debugging CodeXX2 - Low2021, 2025
223Omission of Security-relevant InformationX2 - Low2017, 2021, 2025
234Failure to Handle Missing ParameterX3 - Medium2025
248Uncaught ExceptionX2 - Low2025
252Unchecked Return ValueX2 - Low2025
256Plaintext Storage of a PasswordX3 - Medium2017, 2021, 2025
258Empty Password in Configuration FileX3 - Medium2017, 2021, 2025
259Use of Hard-coded PasswordXX3 - Medium2017, 2021, 2025
261Weak Encoding for PasswordX3 - Medium2017, 2021, 2025
272Least Privilege ViolationX3 - Medium2017, 2021, 2025
273Improper Check for Dropped PrivilegesX3 - Medium2025
282Improper Ownership ManagementX3 - Medium2017, 2021, 2025
284Improper Access ControlX3 - Medium2017, 2021, 2025
285Improper AuthorizationX3 - Medium2017, 2021, 2025
287Improper AuthenticationXX4 - High2017, 2021, 2025
295Improper Certificate ValidationX3 - Medium2017, 2021, 2025
296Improper Following of a Certificate's Chain of TrustX3 - Medium2017, 2021, 2025
297Improper Validation of Certificate with Host MismatchXX3 - Medium2017, 2021, 2025
298Improper Validation of Certificate ExpirationX3 - Medium2017, 2021, 2025
299Improper Check for Certificate RevocationX3 - Medium2017, 2021, 2025
311Missing Encryption of Sensitive DataX3 - Medium2017, 2021, 2025
312Cleartext Storage of Sensitive InformationX3 - Medium2017, 2021, 2025
313Cleartext Storage in a File or on DiskX3 - Medium2017, 2021, 2025
316Cleartext Storage of Sensitive Information in MemoryX3 - Medium2017, 2021, 2025
319Cleartext Transmission of Sensitive InformationX3 - Medium2017, 2021, 2025
321Use of Hard-coded Cryptographic KeyXX3 - Medium2017, 2021, 2025
323Reusing a Nonce, Key Pair in EncryptionX3 - Medium2021, 2025
325Missing Cryptographic StepX3 - Medium2017, 2021, 2025
326Inadequate Encryption StrengthXX3 - Medium2017, 2021, 2025
327Use of a Broken or Risky Cryptographic AlgorithmXX3 - Medium2017, 2021, 2025
329Generation of Predictable IV with CBC ModeX2 - Low2021, 2025
330Use of Insufficiently Random ValuesX3 - Medium2021, 2025
331Insufficient EntropyX3 - Medium2021, 2025
338Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)X3 - Medium2021, 2025
345Insufficient Verification of Data AuthenticityXX4 - High2021, 2025
346Origin Validation ErrorX3 - Medium2021, 2025
347Improper Verification of Cryptographic SignatureX2 - Low2021, 2025
350Reliance on Reverse DNS Resolution for a Security-Critical ActionX3 - Medium2017, 2021, 2025
352Cross-Site Request Forgery (CSRF)XX3 - Medium2021, 2025
354Improper Validation of Integrity Check ValueX3 - Medium2021, 2025
359Exposure of Private Personal Information to an Unauthorized ActorXX2 - Low2017, 2021, 2025
366Race Condition within a ThreadX3 - Medium2025
367Time-of-check Time-of-use (TOCTOU) Race ConditionX3 - Medium2025
377Insecure Temporary FileX3 - Medium2021, 2025
382J2EE Bad Practices: Use of System.exit()X2 - Low2025
384Session FixationXX3 - Medium2017, 2021, 2025
402Transmission of Private Resources into a New Sphere ('Resource Leak')X3 - Medium2021, 2025
421Race Condition During Access to Alternate ChannelX3 - Medium2017, 2021, 2025
426Untrusted Search PathX3 - Medium2021, 2025
427Uncontrolled Search Path ElementX3 - Medium2021, 2025
434Unrestricted Upload of File with Dangerous TypeX4 - High2021, 2025
441Unintended Proxy or Intermediary ('Confused Deputy')X3 - Medium2021, 2025
451User Interface (UI) Misrepresentation of Critical InformationX3 - Medium2021, 2025
470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')X3 - Medium2021, 2025
472External Control of Assumed-Immutable Web ParameterX3 - Medium2021, 2025
479Signal Handler Use of a Non-reentrant FunctionX3 - Medium2025
489Active Debug CodeX3 - Medium2025
497Exposure of Sensitive System Information to an Unauthorized Control SphereX2 - Low2021, 2025
502Deserialization of Untrusted DataXX3 - Medium2017, 2021, 2025
506Embedded Malicious CodeX4 - High2025
511Logic/Time BombX5 - Very High (Critical)2025
522Insufficiently Protected CredentialsXX3 - Medium2017, 2021, 2025
526Cleartext Storage of Sensitive Information in an Environment VariableX2 - Low2017, 2021, 2025
530Exposure of Backup File to an Unauthorized Control SphereX2 - Low2021, 2025
532Insertion of Sensitive Information into Log FileX2 - Low2021, 2025
538Insertion of Sensitive Information into Externally-Accessible File or DirectoryX2 - Low2021, 2025
547Use of Hard-coded, Security-relevant ConstantsX3 - Medium2021, 2025
548Exposure of Information Through Directory ListingX2 - Low2017, 2021, 2025
564SQL Injection: HibernateX4 - High2017, 2021, 2025
566Authorization Bypass Through User-Controlled SQL Primary KeyX3 - Medium2017, 2021, 2025
601URL Redirection to Untrusted Site ('Open Redirect')XX3 - Medium2021, 2025
611Improper Restriction of XML External Entity ReferenceXX3 - Medium2017, 2021, 2025
614Sensitive Cookie in HTTPS Session Without 'Secure' AttributeXX2 - Low2017, 2021, 2025
615Inclusion of Sensitive Information in Source Code CommentsX2 - Low2021, 2025
618Exposed Unsafe ActiveX MethodX5 - Very High (Critical)2017, 2021, 2025
628Function Call with Incorrectly Specified ArgumentsX2 - Low2025
639Authorization Bypass Through User-Controlled KeyX4 - High2017, 2021, 2025
642External Control of Critical State DataX2 - Low2021, 2025
668Exposure of Resource to Wrong SphereXX3 - Medium2021, 2025
676Use of Potentially Dangerous FunctionX3 - Medium2025
693Protection Mechanism FailureXX3 - Medium2025
708Incorrect Ownership AssignmentX4 - High2017, 2021, 2025
732Incorrect Permission Assignment for Critical ResourceX3 - Medium2017, 2021, 2025
749Exposed Dangerous Method or FunctionX4 - High2017, 2021, 2025
757Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')XX3 - Medium2021, 2025
760Use of a One-Way Hash with a Predictable SaltX3 - Medium2017, 2021, 2025
780Use of RSA Algorithm without OAEPX3 - Medium2017, 2021, 2025
798Use of Hard-coded CredentialsX3 - Medium2017, 2021, 2025
829Inclusion of Functionality from Untrusted Control SphereXX3 - Medium2021, 2025
830Inclusion of Web Functionality from an Untrusted SourceX2 - Low2021, 2025
862Missing AuthorizationX2 - Low2017, 2021, 2025
915Improperly Controlled Modification of Dynamically-Determined Object AttributesX3 - Medium2021, 2025
916Use of Password Hash With Insufficient Computational EffortX3 - Medium2017, 2021, 2025
918Server-Side Request Forgery (SSRF)XX3 - Medium2021, 2025
923Improper Restriction of Communication Channel to Intended EndpointsX3 - Medium2017, 2021, 2025
926Improper Export of Android Application ComponentsX3 - Medium2017, 2021, 2025
942Permissive Cross-domain Security Policy with Untrusted DomainsX3 - Medium2017, 2021, 2025
943Improper Neutralization of Special Elements in Data Query LogicXX4 - High2017, 2021, 2025
1174ASP.NET Misconfiguration: Improper Model ValidationX2 - Low2021, 2025
1236Improper Neutralization of Formula Elements in a CSV FileX3 - Medium2017, 2021, 2025
1336Improper Neutralization of Special Elements Used in a Template EngineX5 - Very High (Critical)2017, 2021, 2025
1427Improper Neutralization of Input Used for LLM PromptingX4 - High2017, 2021, 2025