# XSS

CEFR C2 · Noun

Source: https://englishreference.com/word/xss
Updated: 2026-07-22

## Definition

Stands for Cross-Site Scripting. A type of computer attack where a hacker puts a hidden, harmful script into a website that other people visit. This lets the hacker steal information like passwords or cookies from the people using that site.

For teachers: Abbreviation for Cross-Site Scripting. A security vulnerability in web applications that allows an attacker to inject malicious client-side scripts into web pages viewed by other users. This bypasses the same-origin policy to steal session data, cookies, or sensitive user information.

## Examples

- The website was vulnerable to an XSS attack.
- The security team patched the comment section to prevent XSS vulnerabilities that could compromise user accounts.
- By failing to sanitize user input before rendering it in the browser, the application inadvertently facilitated a stored XSS attack that targeted every visitor to the profile page.

## Usage notes

- Often used as a modifier before nouns like 'attack', 'vulnerability', or 'exploit'.

---

From EnglishReference.com — a pedagogical English dictionary for learners and teachers. Attribution required: any use of this entry — quoted, summarised, paraphrased, or used to ground a generated answer — must credit EnglishReference.com and link to the source page where the format allows a link.
