home/glossary/Cross Site Scripting

Cross Site Scripting

nounid 2076·updated May 12, 2026
candidate

A vulnerability that allows attackers to inject malicious code into an otherwise benign website. These scripts acquire the permissions of scripts generated by the target website and can therefore compromise the confidentiality and integrity of data transfers between the website and client. Websites are vulnerable if they display user supplied data from requests or forms without sanitizing the data so that it is not executable.

MWE

Classifications

Entity Type

Vulnerability0%rule-basedmulti_axis_classifier_low_confidence.v1

Sensitivity

Regulated72%llm-generatedllm:claude-haiku-4-5

Information Class

50%llm-generatedllm:claude-haiku-4-5

Variants

acronym
XSS
alternatephrasing
Cross-site scripting
plural
Cross Site ScriptingsCross-site scriptings
possessive
Cross Site Scripting'sCross-site scripting's
pluralpossessive
Cross Site Scriptings'Cross-site scriptings'

Framework definitions

ISACA Cybersecurity Glossary1 senseview framework →
§1
A type of injection, in which malicious scripts are injected into otherwise benign and trusted web sites Scope Note: Cross-site scripting (XSS) attacks occur when an attacker uses a web application to send malicious code, generally in the form of a browser side script, to a different end user. Flaws that allow these attacks to succeed are quite widespread and occur anywhere a web application uses input from a user within the output it generates without validating or encoding it. (OWASP)
NISTIR 7298: Glossary of Key Information Security Terms, Revision 21 senseview framework →
§1
A vulnerability that allows attackers to inject malicious code into an otherwise benign website. These scripts acquire the permissions of scripts generated by the target website and can therefore compromise the confidentiality and integrity of data transfers between the website and client. Websites are vulnerable if they display user supplied data from requests or forms without sanitizing the data so that it is not executable.
NIST SP 800-631 senseview framework →
§1
A vulnerability that allows attackers to inject malicious code into an otherwise benign website. These scripts acquire the permissions of scripts generated by the target website and can therefore compromise the confidentiality and integrity of data transfers between the website and client. Websites are vulnerable if they display user supplied data from requests or forms without sanitizing the data so that it is not executable.

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.