Record WatchRecord
CWE-79 has been the most common vulnerability type for over 24 months
23 July 2026 · Timeframe: Monthly top weakness; multi-month streak
CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) has led the monthly weakness ranking for at least 24 consecutive months. The same class of flaw is being written into new software, month after month, faster than it is being designed out.
Why it matters
A weakness that stays #1 for years is not a fad; it is a structural gap in how software is built. The durable leaders are where prevention pays back the most.
What to do
- CISOs. Make Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') a standing item in your secure-development and testing requirements, not a one-off.
- Lean IT orgs. If you ship code, a improper neutralization of input during web page generation ('cross-site scripting') check belongs in every review; it is the most common flaw for a reason.
- MSPs. Standardize a Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') baseline across clients who build or host software.
Our take
The weaknesses that never leave the top of the list are the ones worth engineering out at the source. Durability is the signal, not novelty.
The data behind this