Common Weakness Enumeration
Common Weakness Enumeration (CWE) is a community-developed catalog of common software weakness types that may lead to security vulnerabilities.
“A community-developed list of common software and hardware weaknesses.”
(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)
View the complete ISTQB GlossaryWhat is Common Weakness Enumeration?
CWE classifies programming weaknesses such as buffer overflows and improper input validation, helping developers prevent security defects.
Weakness catalog: Focuses on coding and design weaknesses.
Prevention: Encourages secure development practices.
Testing value: Supports secure code reviews and security testing.
Real World Example
A regulated product team is preparing a release where Common weakness enumeration appears in reviews, test design conversations, or defect triage rather than as an isolated glossary word.
The risk is that the team treats Common weakness enumeration as interchangeable with nearby ISTQB terms. That makes test scope blurry and can lead to weak evidence for the release decision.
The tester anchors the discussion in the official definition, asks where the concept appears in the product, and designs examples that show the difference between Common weakness enumeration and similar ideas.
The page becomes useful in practice because Common weakness enumeration is connected to a specific testing decision, not memorized as a detached definition.
Practice Questions
Question 1
Which usage BEST reflects CWE?
Question 2
Why link defects to CWE categories?
Test your knowledge with real ISTQB-style questions
You’ve learned Common Weakness Enumeration. Test your understanding with topic-specific questions in our Mock Exams.