xss
Safeguard articles tagged "xss" — guides, analysis, and best practices for software supply chain and application security.
88 articles
An Uploaded File Can Be Two Formats at Once, and Your Validation Only Checked One
A user's file passes every image validation check your upload handler runs. It is also, independently and simultaneously, a valid HTML document, and browser MIME sniffing can choose to render that instead when your response headers do not stop it.
Your Admin Panel Has the Most Access and the Least Review
It can read every customer's data because that is its job, it was built quickly for an audience of colleagues, and it has never been part of a release anyone examined closely.
Inbound Email Is an Unauthenticated API You Forgot You Built
Reply to a notification and it appears in the ticket. Forward a document and it imports. The From header is a string the sender chooses, and it is what most implementations key on.
Jinja2 xmlattr filter XSS (CVE-2024-22195)
CVE-2024-22195 lets attacker-controlled dict keys bypass Jinja2's xmlattr escaping for XSS. Learn affected versions, CVSS/EPSS context, and fixes.
Cross-site scripting (XSS) explained for developers
XSS has topped vulnerability lists for two decades. Here's how reflected, stored, and DOM-based XSS actually work, real incidents, and how to fix them.
angular.io Security: Keeping Your Angular App Safe in 2025
The docs at angular.io teach safe defaults, but recent CVEs in SSR, the HTTP client, and template sanitization show where the framework still needs your attention.
What Is the Bootstrap Latest Version, and Is It Secure?
The Bootstrap latest version is 5.3.8, and knowing your version is a security decision: older Bootstrap releases carry known XSS bugs and rely on end-of-life jQuery.
React and TypeScript security best practices for 2026
A 2025 npm phishing attack hit packages with 2.6 billion weekly downloads. Here's how React and TypeScript teams reduce XSS, API, and dependency risk.
Preventing XSS in Django applications
Django escapes template output by default, but mark_safe() and format_html() misuse routinely reopen the exact XSS holes auto-escaping was built to close.
XSS defaults and escape hatches: React, Vue, and Angular compared
All three major frameworks escape output by default, but each ships a named escape hatch that turns raw HTML back on — and only one sanitizes it automatically.
Preventing XSS in Java Spring and JSP applications
OWASP folded XSS into A03:2021-Injection, present in ~3.37% of tested apps — raw JSP EL output and a missing CSP header are still the two most common causes.
XSS Code Examples: How Cross-Site Scripting Looks in Practice
An XSS code example makes the abstract concrete: here is what vulnerable code looks like for each type of cross-site scripting, and the small change that fixes each one.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.