This page is experimental and may change significantly in future releases.
Incomplete Denylist to Cross-Site Scripting
Properties
id: d3f:CWE-692
- name
- Incomplete Denylist to Cross-Site Scripting
- definition
- The product uses a denylist-based protection mechanism to defend against XSS attacks, but the denylist is incomplete, allowing XSS variants to succeed.
Neighbors
CWE-692 has no direct neighbors in this release.Inferred Relationships
Related Countermeasure Techniques
Related Weaknesses
CWE-692 has no related weaknesses in this release.