XSS (Cross-Site Scripting)
A web vulnerability where attackers inject malicious scripts into trusted websites, which then execute in other users' browsers to steal session tokens or credentials.
Cross-Site Scripting (XSS) is a web application vulnerability where an attacker injects malicious JavaScript into a trusted website. When other users visit the page, the malicious script executes in their browser with the privileges of the trusted site.
XSS attacks can steal session cookies, capture form inputs (including passwords), redirect users to phishing pages, or modify page content. The three main types are Stored XSS (script is saved in the database), Reflected XSS (script is embedded in a URL), and DOM-based XSS (script manipulates the client-side DOM).
Defenses include input validation, output encoding, Content Security Policy (CSP) headers, HttpOnly cookie flags, and secure coding practices. For users, a password manager provides protection by autofilling credentials only on legitimate domains, not on injected forms.
Related reading
Stop sharing passwords in spreadsheets
TeamPassword stores, shares and rotates your team credentials, encrypted end to end.
Trusted by 900+ agencies and small teams worldwide