- Home
- All questions
- Question 465
CISSP study material · question 465 of 500
Why does OWASP's 2025 injection entry have a lower average weighted impact than the severity of SQL injection alone would suggest?
Show the answer
Answer: B. The very large number of cross-site scripting CVEs, a high-frequency but low-impact form, pulls the category average down.
OWASP notes the massive number of reported cross-site scripting CVEs, described as high frequency and low impact, brings down the average weighted impact of the injection category.
Source: OWASP Top 10 A05:2025 (OWASP) — OWASP Top 10:2025 A05 Injection > Background