78 600 000 000
gemiusAdReal, badanie cross-mediowe rynku reklamowego w Polsce, sierpień 2026
Gemius09/2026Poland
Injection of a script that executes in another user's browser. Allows stealing their session, modifying page content, or redirecting them elsewhere.
Attackers don't need server access. Just having an administrator open a page containing their script is enough — and the administrator's session becomes theirs.
Without proper escaping when outputting user-provided content, every form is an entry point. The same vulnerability applies to text generated by AI models.
When outputting anything on a page that came from outside — including from APIs or AI models.
Persistent XSS resides in the database (e.g., comment, profile) and executes for every user who views the page — the most dangerous variant.
Numbers worth knowing
78 600 000 000
gemiusAdReal, badanie cross-mediowe rynku reklamowego w Polsce, sierpień 2026
Gemius09/2026Poland
We use cookies and similar technologies for analytics and personalisation. With your consent we collect, among other things, your activity, device and browser, IP address and the country and internet provider derived from it (profiling), and we remember a referral code from an invitation link for 30 days. We keep the data, including IP addresses, for as long as it is needed for statistics and site security. Details: privacy policy.