CWE

Informational

Common Weakness Enumeration

Definition

CWE (Common Weakness Enumeration) is a community catalog of software and hardware weaknesses organized by category. Unlike CVE, which identifies specific vulnerabilities, CWE classifies the types of weaknesses (for example, CWE-79 for XSS, CWE-89 for SQLi). It is maintained by MITRE and serves as the standard taxonomy for categorizing vulnerabilities.

Impact

Standardized classification of vulnerability typesAnalysis of software weakness trendsImproving secure development processesReference in SAST/DAST tools and scannersRequirement in high-quality bug bounty reports

Examples

Most common CWEs in bug bounty

The most reported CWEs in bug bounty programs include: CWE-79 (XSS), CWE-89 (SQL Injection), CWE-639 (IDOR), CWE-352 (CSRF), CWE-918 (SSRF), CWE-22 (Path Traversal), CWE-78 (OS Command Injection). Knowing the matching CWE improves the quality of the report.

Practice CWE with real labs

Apply what you've learned in safe environments based on real bug bounty reports.

See practice labs
2,482

hunters training

62

labs from real hacks

1,630

completions

$14,790

paid out for these bugs

11 flags captured this week·Real hacks from HackerOne · YesWeHack · Bugcrowd·No commitment·Free Academy
Free · no account

The checklist I run on every new target

47 checks ordered by cost: first what can get you in trouble, then the cheap stuff, and finally the expensive stuff — which is where the big bounties are. I'll send it to your inbox right now.

Unsubscribe in one click, from any email.

BBLabs · bug bounty training

Stop reading about bugs and start hunting them

Create your free account and practice on labs based on real hacks that paid out thousands of euros. The Academy is free forever.

No card · free Academy · cancel anytime