Skip to content

What is Cross-site scripting?

Also called: XSS

The short answer

Cross-site scripting is an attack where malicious code is injected into a page and runs in other visitors' browsers, stealing sessions or data.

Cross-site scripting, explained

Escaping all user-supplied content before displaying it, and a Content Security Policy, prevent it. Modern frameworks escape by default.

Questions people ask about Cross-site scripting

What is Cross-site scripting?

Cross-site scripting is an attack where malicious code is injected into a page and runs in other visitors' browsers, stealing sessions or data.

Part of the Web Encyclopedia by Apex Flow Digital. Definitions are general knowledge, kept current, with no invented statistics.

Reviews

We’re early. Real reviews only.

Apex Flow Digital launched recently. Every purchase comes with a request for honest feedback through our help center. When real buyers write real reviews, they go here — with their permission, by name. Until then, this section stays empty. No fakes. No stock photos. No bullshit.

Used something from the catalog? Leave honest feedback →

While you’re here…