CWE Database
/

CWE-794

Back to CWE list

CWE-794

Incomplete Filtering of Multiple Instances of Special Elements

Variant
Incomplete

Description

The product receives data from an upstream component, but does not filter all instances of a special element before sending it to a downstream component.

{"xhtml:p":["Incomplete filtering of this nature may be applied to:"],"xhtml:ul":[{"xhtml:li":["sequential elements (special elements that appear next to each other) or","non-sequential elements (special elements that appear multiple times in different locations)."]}]}

Common Consequences

Scope

Integrity

Impact

Unexpected State

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now