{"id":4192,"date":"2026-09-21T13:13:59","date_gmt":"2026-09-21T07:43:59","guid":{"rendered":"https:\/\/cybx.in\/blog\/?p=4192"},"modified":"2026-09-21T13:14:00","modified_gmt":"2026-09-21T07:44:00","slug":"what-are-the-different-types-of-cross-site-scripting","status":"publish","type":"post","link":"https:\/\/cybx.in\/blog\/what-are-the-different-types-of-cross-site-scripting\/","title":{"rendered":"What Are the Different Types of Cross-Site Scripting?"},"content":{"rendered":"\n<meta name=\"description\" content=\"Cross-site scripting, usually called XSS, happens when an attacker gets a website to run unwanted code in someone else's browser. The basic idea is simple. T\">\n<meta property=\"og:title\" content=\"What Are the Different Types of Cross-Site Scripting?\">\n<meta property=\"og:description\" content=\"Cross-site scripting, usually called XSS, happens when an attacker gets a website to run unwanted code in someone else's browser. The basic idea is simple. T\">\n<meta name=\"twitter:card\" content=\"summary_large_image\">\n<meta name=\"twitter:title\" content=\"What Are the Different Types of Cross-Site Scripting?\">\n<meta name=\"twitter:description\" content=\"Cross-site scripting, usually called XSS, happens when an attacker gets a website to run unwanted code in someone else's browser. The basic idea is simple. T\">\n\n\n<p>Cross-site scripting, usually called XSS, happens when an attacker gets a website to run unwanted code in someone else&#8217;s browser. The basic idea is simple. The tricky part is that XSS doesn&#8217;t always happen in the same way.<\/p>\n<h2>Stored XSS Keeps the Attack on the Website<\/h2>\n<p>Stored XSS is the one I take most seriously because the harmful code gets saved by the website itself. Imagine a comment section where someone enters something that looks like normal text. If the site stores it without properly handling the input, the code can later run whenever another person opens the affected page.<\/p>\n<h3>Why Stored XSS Can Spread<\/h3>\n<p>Think about a forum or profile page. Raj once spent a morning checking why a test comment kept appearing after he refreshed the page. He stopped reopening the same five tabs every morning once he found the stored input causing it.<\/p>\n<h2>Reflected XSS Depends on the Request<\/h2>\n<p>Reflected XSS works differently. The malicious input usually arrives as part of a request and is immediately reflected back into the webpage without proper handling. A specially crafted link is a common way this happens.<\/p>\n<p>Because the code isn&#8217;t normally saved on the server, the attacker has to get the victim to make the affected request. A fake message containing a strange-looking link could do the job.<\/p>\n<h3>Where Reflected XSS Shows Up<\/h3>\n<p>Search pages are a classic example. A site might display the search term on the results page. If that value is inserted into the page without safe output handling, an attacker can try to manipulate what the browser receives.<\/p>\n<p>\u2022 A search result page that repeats the user&#8217;s query, for example, can become risky if that value isn&#8217;t handled safely.<\/p>\n<p>\u2022 A URL carrying unwanted input is another common route, although the victim still has to open the affected request.<\/p>\n<h2>DOM-Based XSS Happens in the Browser<\/h2>\n<p>DOM-based XSS has a different twist. The problem exists mainly in the browser-side code that changes the page using data it doesn&#8217;t trust.<\/p>\n<p>JavaScript might read something from the URL and then place that value into the page. If the code uses an unsafe method to insert it, the browser can interpret attacker-controlled content as HTML or script.<\/p>\n<p>And this is why looking only at the server isn&#8217;t enough. A website can have perfectly reasonable server responses while its client-side JavaScript still creates an XSS problem.<\/p>\n<h2>The Three Types Can Overlap in Real Attacks<\/h2>\n<p>These categories describe how the malicious input travels, rather than three completely separate vulnerabilities. Stored XSS involves saved input. Reflected XSS sends the input back through a request. DOM-based XSS comes from unsafe handling in browser-side code.<\/p>\n<p>The practical defenses are less mysterious than the names suggest. Treat user input as untrusted. Encode output for its actual context. Use safe DOM APIs where possible. And add protections such as a strong Content Security Policy as another layer.<\/p>","protected":false},"excerpt":{"rendered":"<p>Cross-site scripting, usually called XSS, happens when an attacker gets a website to run unwanted code in someone else&#8217;s browser&#8230;.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-4192","post","type-post","status-publish","format-standard","hentry","category-learn"],"_links":{"self":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts\/4192","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/comments?post=4192"}],"version-history":[{"count":1,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts\/4192\/revisions"}],"predecessor-version":[{"id":4243,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts\/4192\/revisions\/4243"}],"wp:attachment":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/media?parent=4192"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/categories?post=4192"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/tags?post=4192"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}