XSS (Cross-Site Scripting)
Embed This Widget
Add the script tag and a data attribute to embed this widget.
Embed via iframe for maximum compatibility.
<iframe src="https://statuscodefyi.com/iframe/glossary/xss/" width="420" height="400" frameborder="0" style="border:0;border-radius:10px;max-width:100%" loading="lazy"></iframe>
Paste this URL in WordPress, Medium, or any oEmbed-compatible platform.
https://statuscodefyi.com/glossary/xss/
Add a dynamic SVG badge to your README or docs.
[](https://statuscodefyi.com/glossary/xss/)
Use the native HTML custom element.
A security vulnerability where attackers inject malicious scripts into web pages viewed by other users. Stored XSS persists in the database, reflected XSS bounces off the server in the response, and DOM-based XSS manipulates client-side JavaScript. XSS can steal session cookies, redirect users, or deface websites. Defenses include output encoding, Content Security Policy (CSP) headers, and HttpOnly cookies.