Product
SAST Coverage & Rules Zero-Day Discovery Download
Compliance
Compliance Hub OWASP Top 10 CWE Top 25 PCI DSS 4.0.1 MISRA C / C++ 2023 AUTOSAR C++14 ISO 26262 SEI CERT
Compare
vs All SAST Tools vs Coverity vs Veracode vs Snyk vs Mythos AI vs GPT-5.4 Cyber Download
Compliance  /  CWE Top 25
CWE Top 25

The 25 most dangerous
weaknesses - detected & mapped.

PhantomYerra's rules carry exact CWE identifiers, so findings map directly to the MITRE CWE Top 25 Most Dangerous Software Weaknesses. The table below shows the highest-weighted entries.

Top 25
weaknesses mapped
16
languages
Exact
CWE-ID per finding

Most dangerous software weaknesses (highest-weighted shown)

CWEWeaknessDetected
CWE-787Out-of-bounds WriteYes
CWE-79Cross-site ScriptingYes
CWE-89SQL InjectionYes
CWE-416Use After FreeYes
CWE-78OS Command InjectionYes
CWE-20Improper Input ValidationYes
CWE-125Out-of-bounds ReadYes
CWE-22Path TraversalYes
CWE-352Cross-Site Request ForgeryYes
CWE-434Unrestricted File UploadYes
CWE-862Missing AuthorizationYes
CWE-476NULL Pointer DereferenceYes
CWE-287Improper AuthenticationYes
CWE-190Integer OverflowYes
CWE-502Deserialization of Untrusted DataYes
CWE-77Command InjectionYes
CWE-119Improper Memory Buffer RestrictionYes
CWE-798Hard-coded CredentialsYes
CWE-918Server-Side Request ForgeryYes
CWE-306Missing AuthenticationYes

Turn findings into CWE Top 25 evidence

Every PhantomYerra finding carries its CWE and the standard IDs it satisfies, so a one-click compliance report maps findings to CWE Top 25 automatically - alongside the EU Cyber Resilience Act and more.