Glossary Security

Cross-site scripting (XSS)

Cross-site scripting (XSS) is a vulnerability in which an attacker gets a website to deliver malicious script to other users' browsers, where it runs with the site's privileges.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

It happens when user input is placed in a page without being escaped, for example a comment containing a <script> tag. A script that runs can read cookies, change the page or act as the user. Defences: escape output for its context (see HTML Entity Encode), use a strict Content Security Policy (CSP), mark session cookies HttpOnly and prefer frameworks that escape by default.

Try these tools

See also

  • Glossary Content Security Policy (CSP)
    A Content Security Policy is an HTTP header that tells the browser which sources of scripts, styles.
  • Glossary CSRF
    CSRF (cross-site request forgery) is an attack that tricks a logged-in user's browser into sending an unwanted request to a site where they.
  • Glossary SQL injection
    SQL injection is an attack in which input is crafted so that part of it is executed as database commands.
  • Glossary Cookie
    A cookie is a small piece of data a website stores in your browser and sends back with later requests.
AdSense Placeholder
Slot: footer_leaderboard