Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
Key takeaways
- XSS is an injection flaw that runs attacker - controlled scripts in a user’s browser.
- The three main types are reflected, stored, and DOM - based.
- Prevent XSS by validating input, encoding output, and applying a strict Content - Security - Policy.
- Decloak’s free scan flags dangerous JavaScript patterns (e.g. eval, innerHTML sinks, wildcard postMessage) in its JavaScript CVE layer.
What is cross - site scripting (XSS)?
Cross - site scripting (XSS) is a class of injection attacks where an attacker injects malicious scripts into pages that users trust. The browser cannot tell the injected code from legitimate content, so it executes the script with the victim’s privileges.
Why does XSS matter?
When an XSS payload runs, the attacker can steal cookies, hijack sessions, rewrite page content, or redirect the user to phishing sites. These outcomes let attackers impersonate users and compromise sensitive data, making XSS one of the most common web security findings.
What are the three types of XSS?
| Type | Description |
|---|---|
| Reflected XSS | The payload is sent as part of the request (for example in a URL) and the server mirrors it back in the response. The script runs when the victim clicks the crafted link. |
| Stored XSS | The malicious script is saved on the server - in a database, comment field, or file - and later served to any user who views that content. |
| DOM - based XSS | The payload never touches the server. It is injected and executed entirely on the client by manipulating the DOM with unsafe JavaScript APIs. |
How does an XSS attack work?
- Find an injection point - a parameter, form field, or DOM API that accepts user - controlled data.
- Insert a script - typically
<script>alert(1)</script>or a more stealthy payload that readsdocument.cookie. - Trigger rendering - the server includes the payload in its HTML output (reflected or stored) or the client - side code writes it into the DOM (DOM - based).
- Browser executes - because the content is treated as trusted, the browser runs the script with the victim’s session cookies and permissions.
What concrete steps stop XSS?
- Validate input - reject unexpected characters or enforce a whitelist of allowed values for each field.
- Encode output - apply contextual encoding before inserting data into HTML, attributes, JavaScript, CSS, or URLs. For HTML content, use HTML - entity encoding.
- Use a strict Content - Security - Policy - set
script-srcto'self'and avoidunsafe-inline. Includeobject-src 'none'and enableupgrade-insecure-requests. - Avoid dangerous APIs - do not use
eval(),new Function(),innerHTML,document.write(), or wildcardpostMessagetargets. Prefer safe DOM methods liketextContentand specificpostMessageorigins. - Sanitize HTML - if you must allow user - generated markup, pass it through a proven sanitizer such as DOMPurify before rendering.
- Perform regular scans - automated tools can spot unencoded outputs and risky patterns before attackers find them.
How can Decloak help you detect XSS?
- Layer 4 (JavaScript CVE scanning) checks every JavaScript file served to the page for known vulnerable libraries and for dangerous patterns like
eval(),innerHTMLsinks, and wildcardpostMessagetargets. It does not scan for exposed secrets, but it flags code that commonly leads to XSS. - Free scan runs this layer in about 15 seconds and returns a graded report with a list of findings, the affected file, and a short remediation note.
- Paid tiers add deeper analysis and can combine the findings with Active Testing (Layer 8) if you consent, which safely attempts to trigger the flagged XSS vectors to confirm exploitability.
Example: fixing a reflected XSS in a search parameter
// vulnerable code
const query = req.query.q; // attacker - controlled
res.send(`<h1>Results for ${query}</h1>`);
Fix - encode the value before insertion:
const query = req.query.q;
const safe = escapeHtml(query); // use a library like he or lodash.escape
res.send(`<h1>Results for ${safe}</h1>`);
The escapeHtml function converts <, >, &, ", and ' to HTML entities, breaking any injected script.
When to use additional layers
If you suspect a complex DOM - based flaw, consider enabling Decloak’s Active Testing (available on Starter+ plans). It will attempt safe, non - destructive probes such as forced browsing and reflected - input canaries to confirm whether the flagged pattern is actually exploitable.
Summary
Cross - site scripting lets attackers run code in a user’s browser by abusing unchecked data. Understanding the three XSS types, applying input validation, output encoding, a strict CSP, and avoiding dangerous JavaScript APIs are the core defenses. Decloak’s free scan quickly highlights risky patterns, and paid tiers can confirm exploitability with safe active testing.
Related guides
How to Fix a Missing Content - Security - Policy Header
Learn concrete steps to add, test, and harden a Content - Security - Policy header, from server configuration to iterative reporting and verification.
Is HTTP 1.1 a security risk?
HTTP 1.1 is not a direct vulnerability, but its plain - text design and parsing ambiguities can create attack surfaces that need mitigation, especially when not used over TLS.
Is JavaScript a security risk?
JavaScript can be a major attack surface because injected scripts run with the same privileges as the page, but proper sanitization, CSP, and safe frameworks eliminate most risks.