Skip to content

Topic

Stored cross-site scripting

A web vulnerability class in which attacker-supplied script is saved by the application and later executed in the browsers of other users who view the affected content.

Current clusters

build1 publisher

An <object> tag turns an uploaded SVG into stored XSS for every visitor

OopsSec Store, a deliberately vulnerable Next.js app, lets an admin-uploaded SVG run JavaScript in every visitor's browser. It works because the server trusts the client-set Content-Type and the product page renders SVGs through an <object> tag.

Publishers:dev.to

Reality

Evidence62
Adoption
Insufficient
Hype gap+8
Incentives40
Confidence72