Inline Cascading Style Sheets (CSS)

Overview

When using CSS style tags and attributes, the HTML parser switches to CDATA or raw text context, which is prone to code injection. For this reason, using inline CSS is considered unsafe and should be avoided.

Business Impact

Suboptimal resource allocation, increased costs, and delayed time-to-market for new features and products.

Resources

Frequent

Incidence

How common is this issue?
27%19%
arrow down7%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
10 months3 months
arrow down74%
shorter
BenchmarkWith Clayton

Frameworks

EasyiconIntentionaliconReadabilityiconDesign StandardsiconA03:2021 – Injectionicon