CWE-692: Incomplete Denylist to Cross-Site Scripting

low-risk

The product uses a denylist-based protection mechanism to defend against XSS attacks, but the denylist is incomplete, allowing XSS variants to succeed.

Abstraction: Compound

Common Consequences

Confidentiality Execute Unauthorized Code or Commands

Real-World Examples (5)

CVE CVSS EPSS KEV
CVE-2023-26047 6.5 0.3%
CVE-2024-30924 4.6 0.2%
CVE-2024-52305 6.5 0.1%
CVE-2025-49590 6.1 0.0%
CVE-2025-20240 6.1 0.0%
0
/ 100
low-risk
Active Threat 0/50 · Minimal
Exploit Availability 0/50 · Minimal