Common Web Vulnerabilities

Cross-site scripting (XSS)

XSS occurs when attacker-controlled content reaches a browser execution context without appropriate handling. The correct defense depends on context.

  • Prefer safe DOM APIs over HTML injection.
  • Contextually encode untrusted data.
  • Use Content Security Policy as defense in depth.
  • Sanitize HTML only when HTML is intentionally supported.
Lab only

Practice XSS with intentionally vulnerable training applications or your own local project, never against a site without authorization.

Lesson complete?Use the next lesson to continue the learning path.