Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-692

Incomplete Denylist to Cross-Site Scripting

The product uses a denylist-based protection mechanism to defend against XSS attacks, but the denylist is incomplete, allowing XSS variants to succeed.

9
Assigned CVEs
451st
Commonality Rank
4.8
Avg CVSS
0.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-692 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 3, 2023
3 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-42214MEDIUM
HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web
Jul 17, 20265.327NONO
CVE-2026-15295MEDIUM
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due
Jul 10, 20264.426NONO
CVE-2025-20240MEDIUM
A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack (XSS)
Sep 24, 20256.123NONO
CVE-2024-23569MEDIUM
HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
Jul 17, 20264.322NONO
CVE-2023-26047MEDIUM
teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. In teler-waf prior to version v0.2.0 is vulnerable to a bypass attack
Mar 3, 20236.121NONO
CVE-2025-49590MEDIUM
CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however thi
Jun 18, 20256.118NONO
CVE-2024-52305MEDIUM
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a n
Nov 13, 20244.817NONO
CVE-2024-30924MEDIUM
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.
Apr 18, 20244.616NONO
CVE-2025-53904LOW
The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` contains code that could make the website vulnerable to cross-s
Jul 16, 20251.311NONO
View all 9 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
11%
1.0-1.9
2.0-2.9
3.0-3.9
44%
10%
4.0-4.9
11%
19%
5.0-5.9
33%
16%
6.0-6.9
26%
7.0-7.9
11%
8.0-8.9
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products