Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-592 — Stored XSS
CAPEC-592

Stored XSS

TLP:CLEAR

Description

Typical severity: Very High. Likelihood of attack: High. An adversary utilizes a form of Cross-site Scripting (XSS) where a malicious script is persistently "stored" within the data storage of a vulnerable web application as valid input.

Mitigation

Use browser technologies that do not allow client-side scripting. | Utilize strict type, character, and encoding enforcement. | Ensure that all user-supplied input is validated before being stored.

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.