Back to Guides
Guide7 October 2026

What is cross - site scripting (XSS) and how to prevent it

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. What is cross - site scripting (XSS)?
  3. Why does XSS matter?
  4. What are the three types of XSS?
  5. How does an XSS attack work?
  6. What concrete steps stop XSS?
  7. How can Decloak help you detect XSS?
  8. Example: fixing a reflected XSS in a search parameter
  9. When to use additional layers
  10. Summary

Key takeaways

What is cross - site scripting (XSS)?

Cross - site scripting (XSS) is a class of injection attacks where an attacker injects malicious scripts into pages that users trust. The browser cannot tell the injected code from legitimate content, so it executes the script with the victim’s privileges.

Why does XSS matter?

When an XSS payload runs, the attacker can steal cookies, hijack sessions, rewrite page content, or redirect the user to phishing sites. These outcomes let attackers impersonate users and compromise sensitive data, making XSS one of the most common web security findings.

What are the three types of XSS?

TypeDescription
Reflected XSSThe payload is sent as part of the request (for example in a URL) and the server mirrors it back in the response. The script runs when the victim clicks the crafted link.
Stored XSSThe malicious script is saved on the server - in a database, comment field, or file - and later served to any user who views that content.
DOM - based XSSThe payload never touches the server. It is injected and executed entirely on the client by manipulating the DOM with unsafe JavaScript APIs.

How does an XSS attack work?

  1. Find an injection point - a parameter, form field, or DOM API that accepts user - controlled data.
  2. Insert a script - typically <script>alert(1)</script> or a more stealthy payload that reads document.cookie.
  3. Trigger rendering - the server includes the payload in its HTML output (reflected or stored) or the client - side code writes it into the DOM (DOM - based).
  4. Browser executes - because the content is treated as trusted, the browser runs the script with the victim’s session cookies and permissions.

What concrete steps stop XSS?

  1. Validate input - reject unexpected characters or enforce a whitelist of allowed values for each field.
  2. Encode output - apply contextual encoding before inserting data into HTML, attributes, JavaScript, CSS, or URLs. For HTML content, use HTML - entity encoding.
  3. Use a strict Content - Security - Policy - set script-src to 'self' and avoid unsafe-inline. Include object-src 'none' and enable upgrade-insecure-requests.
  4. Avoid dangerous APIs - do not use eval(), new Function(), innerHTML, document.write(), or wildcard postMessage targets. Prefer safe DOM methods like textContent and specific postMessage origins.
  5. Sanitize HTML - if you must allow user - generated markup, pass it through a proven sanitizer such as DOMPurify before rendering.
  6. Perform regular scans - automated tools can spot unencoded outputs and risky patterns before attackers find them.

How can Decloak help you detect XSS?

Example: fixing a reflected XSS in a search parameter

// vulnerable code
const query = req.query.q; // attacker - controlled
res.send(`<h1>Results for ${query}</h1>`);

Fix - encode the value before insertion:

const query = req.query.q;
const safe = escapeHtml(query); // use a library like he or lodash.escape
res.send(`<h1>Results for ${safe}</h1>`);

The escapeHtml function converts <, >, &, ", and ' to HTML entities, breaking any injected script.

When to use additional layers

If you suspect a complex DOM - based flaw, consider enabling Decloak’s Active Testing (available on Starter+ plans). It will attempt safe, non - destructive probes such as forced browsing and reflected - input canaries to confirm whether the flagged pattern is actually exploitable.

Summary

Cross - site scripting lets attackers run code in a user’s browser by abusing unchecked data. Understanding the three XSS types, applying input validation, output encoding, a strict CSP, and avoiding dangerous JavaScript APIs are the core defenses. Decloak’s free scan quickly highlights risky patterns, and paid tiers can confirm exploitability with safe active testing.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary