Common Weakness Scoring System
Common Weakness Scoring System (CWSS) is a framework for evaluating and prioritizing software weaknesses based on factors such as likelihood, impact, and exploitability.
“A standard for assessing software weaknesses and vulnerabilities in a consistent, flexible, and open manner.”
(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)
View the complete ISTQB GlossaryWhat is Common Weakness Scoring System?
CWSS helps organizations determine which software weaknesses should be addressed first by assigning scores using multiple technical and business factors.
Prioritization: Helps rank weaknesses for remediation.
Risk factors: Considers technical and environmental characteristics.
Decision support: Assists security teams in planning improvements.
Real World Example
A regulated product team is preparing a release where Common weakness scoring system appears in reviews, test design conversations, or defect triage rather than as an isolated glossary word.
The risk is that the team treats Common weakness scoring system as interchangeable with nearby ISTQB terms. That makes test scope blurry and can lead to weak evidence for the release decision.
The tester anchors the discussion in the official definition, asks where the concept appears in the product, and designs examples that show the difference between Common weakness scoring system and similar ideas.
The page becomes useful in practice because Common weakness scoring system is connected to a specific testing decision, not memorized as a detached definition.
Practice Questions
Question 1
CWSS is MOST useful for…
Question 2
Which confusion is COMMON with CWSS?
Test your knowledge with real ISTQB-style questions
You’ve learned Common Weakness Scoring System. Test your understanding with topic-specific questions in our Mock Exams.