Cross-Site Scripting (XSS)
A web vulnerability that lets an attacker inject malicious script into pages viewed by other users, so that the script runs in the victim's browser with the privileges of the vulnerable site.
XSS arises when an application includes untrusted data in a web page without encoding it correctly for the context in which it appears. Stored XSS saves the payload on the server, for example in a comment or profile field, and serves it to every visitor. Reflected XSS returns the payload immediately from a request parameter, typically through a crafted link. DOM-based XSS occurs entirely in client-side JavaScript that writes untrusted data into the page.
Because injected script runs within the trusted origin, it can read data on the page, perform actions as the logged-in user, capture keystrokes or redirect to phishing pages, and it can steal session cookies that lack the HttpOnly attribute. XSS is among the most frequently reported web vulnerabilities, is catalogued as CWE-79 and was merged into the injection category in the OWASP Top 10 2021.
Prevention relies on context-aware output encoding, frameworks that escape output by default, sanitisation of any user-supplied HTML with a well-maintained library and avoidance of APIs that insert raw HTML. A strict Content Security Policy limits the impact of any remaining flaw, and the HttpOnly attribute keeps session cookies out of reach of scripts. Testing combines code review, static analysis and dynamic scanning.
Key points
- Three main types: stored, reflected and DOM-based.
- Context-aware output encoding is the core defence.
- Content Security Policy reduces impact but does not replace encoding.
- Catalogued as CWE-79 within the OWASP Top 10 injection category.
Where AiVibe comes in
AiVedha.ai's automated website security audit covers XSS among more than 170 checks, with severity ratings and remediation steps in its report.
Related terms
- Content Security Policy (CSP)Cybersecurity & Compliance
- Cookie Security AttributesCybersecurity & Compliance
- OWASP Top 10Cybersecurity & Compliance
- Cross-Site Request Forgery (CSRF)Cybersecurity & Compliance
- Dynamic Application Security Testing (DAST)Cybersecurity & Compliance
- HTTP Security HeadersCybersecurity & Compliance