Common Weakness Enumeration

    CWE Definition / CWE-83

    CWE-83: Improper Neutralization of Script in Attributes in a Web Page

    The product does not neutralize or incorrectly neutralizes javascript: or other URIs from dangerous attributes within tags, such as onmouseover, onload, onerror, or style.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')