Cyber Resilience

Weakness of the WeekWeekly

Weakness of the week: CWE-79 (Cross-site Scripting) leads this week's new CVEs

Updated 12 August 2026 · Timeframe: CVEs published in the last 7 days

CWE-79 · Cross-site Scripting166CWE-862 · Missing Authorization144CWE-122 · Heap-based Buffer Overflow122CWE-22 · Path Traversal114CWE-416 · Use After Free105CWE-89 · SQL Injection99
Most common weakness types in this week's new CVEs · security-resilience.ai

Across CVEs published in the last 7 days, the most common weakness type is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), tagged on 166. The chart ranks the week's top weakness classes — the flaw patterns showing up most in fresh disclosures right now.

Why it matters

Which weakness types dominate this week's disclosures tells you where new exposure is concentrating, and which classes of defect to expect more of in the products you run.

What to do

Our take

Naming the week's dominant weakness type turns a stream of CVEs into a pattern you can actually design against.

Earlier issues

Past states of this signal, most recent first.

08 August 2026 Weakness of the week: CWE-79 (Cross-site Scripting) leads this week's new CVEs

Timeframe: CVEs published in the last 7 days

CWE-79 · Cross-site Scripting174CWE-862 · Missing Authorization131CWE-22 · Path Traversal92CWE-89 · SQL Injection90CWE-918 · Server-Side Request Forgery73CWE-74 · Injection61

Across CVEs published in the last 7 days, the most common weakness type is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), tagged on 174. The chart ranks the week's top weakness classes — the flaw patterns showing up most in fresh disclosures right now.

03 August 2026 Weakness of the week: CWE-79 (Cross-site Scripting) leads this week's new CVEs

Timeframe: CVEs published in the last 7 days

CWE-79 · Cross-site Scripting180CWE-20 · Improper Input Validation117CWE-89 · SQL Injection116CWE-862 · Missing Authorization90CWE-22 · Path Traversal81CWE-200 · Exposure of Sensitive Information…80

Across CVEs published in the last 7 days, the most common weakness type is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), tagged on 180. The chart ranks the week's top weakness classes — the flaw patterns showing up most in fresh disclosures right now.

29 July 2026 Weakness of the week: CWE-79 (Cross-site Scripting) leads this week's new CVEs

Timeframe: CVEs published in the last 7 days

CWE-79 · Cross-site Scripting195CWE-862 · Missing Authorization118CWE-22 · Path Traversal79CWE-89 · SQL Injection78CWE-284 · Improper Access Control59CWE-918 · Server-Side Request Forgery55

Across CVEs published in the last 7 days, the most common weakness type is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), tagged on 195. The chart ranks the week's top weakness classes — the flaw patterns showing up most in fresh disclosures right now.

24 July 2026 Weakness of the week: CWE-284 (Improper Access Control) leads this week's new CVEs

Timeframe: CVEs published in the last 7 days

CWE-284 · Improper Access Control672CWE-306 · Missing Authentication for Critic…259CWE-79 · Cross-site Scripting179CWE-269 · Improper Privilege Management176CWE-200 · Exposure of Sensitive Information…139CWE-862 · Missing Authorization137

Across CVEs published in the last 7 days, the most common weakness type is CWE-284 (Improper Access Control), tagged on 672. The chart ranks the week's top weakness classes — the flaw patterns showing up most in fresh disclosures right now.