Cross-Site Scripting

XSS

noun (acronym) /ˌeks.esˈes/

A security vulnerability where an attacker injects malicious scripts into web pages viewed by other users. Prevented by escaping user-supplied output and using a Content Security Policy (CSP). Ranked in the OWASP Top 10.

"The XSS vulnerability allowed attackers to inject a script into comment fields, stealing session cookies from anyone who viewed the page."

Frequently Asked Questions

What does "XSS" mean in IT?

A security vulnerability where an attacker injects malicious scripts into web pages viewed by other users. Prevented by escaping user-supplied output and using a Content Security Policy (CSP). Ranked in the OWASP Top 10.

What does XSS stand for?

XSS stands for "Cross-Site Scripting".

How do you pronounce "XSS"?

"XSS" is pronounced /ˌeks.esˈes/. Use the "Listen" button above to hear it spoken aloud.