## Securing Against Cross-Site Scripting (XSS)
Cross-Site Scripting (XSS) occurs when an attacker injects malicious client-side scripts into web pages viewed by other users.
### Types of XSS
1. **Stored XSS**: The script is permanently stored on the target server (e.g. in database comments).
2. **Reflected XSS**: The script is reflected off the web server in an immediate error response.
3. **DOM-based XSS**: The vulnerability exists entirely in the client-side JavaScript code.
### Mitigation Strategies
- **HTML Entity Encoding**: Escape special characters like `<`, `>`, `&`, and `"` to prevent the browser from executing them as script tags.
- **Content Security Policy (CSP)**: Set strict HTTP response headers to restrict the sources from which scripts can be loaded.
How to Secure Your Web Applications Against XSS Attacks
"Learn about Cross-Site Scripting (XSS), its types, and how to protect web applications using input escaping and content security policies."
🛠️ Run calculations inside your browser
We provide a secure, native client-side tool matching this article topic. Perform your conversions, format tags, or test code values locally.