CWE-692: Incomplete Denylist to Cross-Site Scripting

The product uses a denylist-based protection mechanism to defend against XSS attacks, but the denylist is incomplete, allowing XSS variants to succeed.

9 tracked CVEs are classified under this weakness.

Highest-risk vulnerabilities

Recently published

Browse the full CVE database