Safeguard
Tag

xss

Safeguard articles tagged "xss" — guides, analysis, and best practices for software supply chain and application security.

88 articles

Application Security

An Uploaded File Can Be Two Formats at Once, and Your Validation Only Checked One

A user's file passes every image validation check your upload handler runs. It is also, independently and simultaneously, a valid HTML document, and browser MIME sniffing can choose to render that instead when your response headers do not stop it.

Sep 18, 20266 min read
Application Security

Your Admin Panel Has the Most Access and the Least Review

It can read every customer's data because that is its job, it was built quickly for an audience of colleagues, and it has never been part of a release anyone examined closely.

Sep 18, 20265 min read
Application Security

Inbound Email Is an Unauthenticated API You Forgot You Built

Reply to a notification and it appears in the ticket. Forward a document and it imports. The From header is a string the sender chooses, and it is what most implementations key on.

Sep 18, 20265 min read
Vulnerability Analysis

Jinja2 xmlattr filter XSS (CVE-2024-22195)

CVE-2024-22195 lets attacker-controlled dict keys bypass Jinja2's xmlattr escaping for XSS. Learn affected versions, CVSS/EPSS context, and fixes.

Aug 8, 20267 min read
Vulnerability Analysis

Cross-site scripting (XSS) explained for developers

XSS has topped vulnerability lists for two decades. Here's how reflected, stored, and DOM-based XSS actually work, real incidents, and how to fix them.

Aug 3, 20267 min read
Open Source

angular.io Security: Keeping Your Angular App Safe in 2025

The docs at angular.io teach safe defaults, but recent CVEs in SSR, the HTTP client, and template sanitization show where the framework still needs your attention.

Jul 25, 20266 min read
Security

What Is the Bootstrap Latest Version, and Is It Secure?

The Bootstrap latest version is 5.3.8, and knowing your version is a security decision: older Bootstrap releases carry known XSS bugs and rely on end-of-life jQuery.

Jul 18, 20266 min read
Application Security

React and TypeScript security best practices for 2026

A 2025 npm phishing attack hit packages with 2.6 billion weekly downloads. Here's how React and TypeScript teams reduce XSS, API, and dependency risk.

Jul 15, 20266 min read
Application Security

Preventing XSS in Django applications

Django escapes template output by default, but mark_safe() and format_html() misuse routinely reopen the exact XSS holes auto-escaping was built to close.

Jul 14, 20266 min read
Application Security

XSS defaults and escape hatches: React, Vue, and Angular compared

All three major frameworks escape output by default, but each ships a named escape hatch that turns raw HTML back on — and only one sanitizes it automatically.

Jul 14, 20266 min read
Application Security

Preventing XSS in Java Spring and JSP applications

OWASP folded XSS into A03:2021-Injection, present in ~3.37% of tested apps — raw JSP EL output and a missing CSP header are still the two most common causes.

Jul 13, 20266 min read
AppSec

XSS Code Examples: How Cross-Site Scripting Looks in Practice

An XSS code example makes the abstract concrete: here is what vulnerable code looks like for each type of cross-site scripting, and the small change that fixes each one.

Jul 11, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.