StudyToCert

All certifications / CISSP / Lessons

ISC2 CISSP 2024 outline · Domain 8: Software development security

Common weaknesses: injection, XSS, CSRF, buffer overflow, race conditions, insecure deserialization

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

A small number of weakness types account for a large share of software vulnerabilities. The exam expects you to recognize each one from a scenario, understand why it happens and name the primary defenses. You do not need to know how to exploit them; you need to know how they arise, how to spot them in a description, and which control addresses each root cause.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study plan