Code vulnerable to cross-site scripting (XSS)

Overview

Cross-site scripting (XSS) attacks cover a broad range of attacks where malicious HTML or client-side scripting is provided to a Web application. The Web application includes malicious scripting in a response to a user of the Web application.

Business Impact

Increased risk of data breaches, financial loss, and reputational harm. Eroding customer trust and confidence.

Resources

Very Frequent

Incidence

How common is this issue?
42%20%
arrow down22%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
2 years9 months
arrow down68%
shorter
BenchmarkWith Clayton

Frameworks

TrustediconSecureiconSession SecurityiconSession ManagementiconA03:2021 – Injectionicon