Back to Glossary

What is Cross-Site Scripting (XSS)?

Definition

A vulnerability where an attacker injects malicious client-side scripts into a trusted website, executing code in the victims' browsers.

Security Impact

Can lead to session hijacking, credential theft, and unauthorized actions on behalf of the user.

How to Remediate

Implement strict Content Security Policy (CSP), sanitize inputs, and use safe frameworks like React that automatically escape HTML.

Want to automatically detect and block Cross-Site Scripting (XSS) vulnerabilities in your CI/CD pipeline?

Start scanning with Bryxe
Put the definition into practice: security field guides →