Common Weakness Enumeration

    CWE Definition / CWE-830

    CWE-830: Inclusion of Web Functionality from an Untrusted Source

    The product includes web functionality (such as a web widget) from another domain, which causes it to operate within the domain of the product, potentially granting total access and control of the product to the untrusted source.

    Published:8 Dec 2010
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-829: Inclusion of Functionality from Untrusted Control Sphere