Skip to content
XSSAKRONIMY
AcronymsAbbreviations everyone uses and few explain

XSS

Cross-Site Scripting

Injection of a script that executes in another user's browser. Allows stealing their session, modifying page content, or redirecting them elsewhere.

Why it matters

Attackers don't need server access. Just having an administrator open a page containing their script is enough — and the administrator's session becomes theirs.

What's missing without it

Without proper escaping when outputting user-provided content, every form is an entry point. The same vulnerability applies to text generated by AI models.

When it is used

When outputting anything on a page that came from outside — including from APIs or AI models.

How we use it

Persistent XSS resides in the database (e.g., comment, profile) and executes for every user who views the page — the most dangerous variant.

Numbers worth knowing

XSS in data

78 600 000 000

gemiusAdReal, badanie cross-mediowe rynku reklamowego w Polsce, sierpień 2026

Gemius09/2026Poland

Related terms