# XSS

XSS (cross-site scripting) is a web security attack in which malicious code is injected into a website and executed in a user's browser.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## \[webapps\] Bludit CMS - Stored XSS

DevFeed: [\[webapps\] Bludit CMS - Stored XSS](<https://devfeed.tech/articles/webapps-bludit-cms-stored-xss-34763.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52670>)

Author: Saud Alenazi

Published: 2026-09-01T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [XSS](<https://devfeed.tech/topics/xss.md>), [Content Management System](<https://devfeed.tech/topics/cms.md>), [webapps](<https://devfeed.tech/topics/webapps.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cms](<https://devfeed.tech/tags/cms.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [stored](<https://devfeed.tech/tags/stored.md>), [webapps](<https://devfeed.tech/tags/webapps.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

A concise exploit entry describing stored cross-site scripting (XSS) in Bludit CMS for web applications across multiple platforms.

### Source excerpt

Bludit CMS - Stored XSS

## \[webapps\] CubeCart 6.7.4 - Stored XSS

DevFeed: [\[webapps\] CubeCart 6.7.4 - Stored XSS](<https://devfeed.tech/articles/webapps-cubecart-6-7-4-stored-xss-34755.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52662>)

Author: Mikail KOCADAĞ

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [XSS](<https://devfeed.tech/topics/xss.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-54645](<https://devfeed.tech/tags/cve-2026-54645.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [stored](<https://devfeed.tech/tags/stored.md>), [webapps](<https://devfeed.tech/tags/webapps.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

An exploit entry for CubeCart 6.7.4 describing a stored cross-site scripting vulnerability identified as CVE-2026-54645. It is categorized as a web applications exploit for multiple platforms.

### Source excerpt

CubeCart 6.7.4 - Stored XSS

## \[webapps\] C-MOR 6.0104 - Cross-Site Scripting (XSS)

DevFeed: [\[webapps\] C-MOR 6.0104 - Cross-Site Scripting (XSS)](<https://devfeed.tech/articles/webapps-c-mor-6-0104-cross-site-scripting-xss-34758.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52665>)

Author: Samir Shamdin

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [webapps](<https://devfeed.tech/topics/webapps.md>), [XSS](<https://devfeed.tech/topics/xss.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-51133](<https://devfeed.tech/tags/cve-2026-51133.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [webapps](<https://devfeed.tech/tags/webapps.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

A C-MOR 6.0104 entry documenting a Cross-Site Scripting (XSS) exploit identified as CVE-2026-51133.

### Source excerpt

C-MOR 6.0104 - Cross-Site Scripting (XSS)

## Keycloak 26.6.2 released

DevFeed: [Keycloak 26.6.2 released](<https://devfeed.tech/articles/keycloak-26-6-2-released-31772.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/05/keycloak-2662-released>)

Author: Keycloak Team

Published: 2026-05-19T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>), [XSS](<https://devfeed.tech/topics/xss.md>)

Tags: [2](<https://devfeed.tech/tags/2.md>), [2026](<https://devfeed.tech/tags/2026.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [permission](<https://devfeed.tech/tags/permission.md>), [pii](<https://devfeed.tech/tags/pii.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

Keycloak 26.6.2 is a security-focused release that fixes multiple vulnerabilities, including denial-of-service issues, request smuggling, access-control flaws, stored XSS, WebAuthn policy bypass, token disclosure, account takeover, and PII enumeration. It also includes enhancements and bug fixes.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #47485 CVE-2026-33871 HTTP/2 CONTINUATION Frame Flood Denial of Service #47486 CVE-2026-33870 RFC violation: HTTP Request Smuggling primitive via Chunked Extension Quoted-String Parsing #47932 [CVE-2026-4628] Improper Access Control on Keycloak Server through UMA resource management endpoints via PUT parameters authorization-services #48049 [CVE-2026-37980] Stored XSS in select-organization.ftl - FreeMarker HTML-escape insufficient in inline JS handler organizations #48275 CVE-2026-5588 Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules core #48388 [CVE-2026-6856] Acceptable AAGUID policy bypass via packed self-attestation in WebAuthn registration authentication/webauthn #48570 [CVE-2026-0636, CVE-2026-3505, CVE-2026-5598] Multiple bouncycastle CVEs core #49108 [CVE-2026-7307] Denial of service when sending a crafted request to the /saml endpoint #49109 [CVE-2026-7504] Security Vulnerability Report: Redirect URI Validation Bypass in Keycloak #49110 [CVE-2026-7571] Access token disclosure and implicit flow bypass via forged client data #49111 [CVE-2026-7507] Session fixation in OIDC login flow leading to account takeover #49112 [CVE-2026-37982] Execute-actions token replay allows unauthorized WebAuthn credential enrollment on victim account #49113 [CVE-2026-37979] OIDC Introspection endpoint does not enforce audience restriction, leaking claims from lightweight access tokens #49114 [CVE-2026-37978] Cross-role PII leakage via evaluate-scopes endpoints bypasses user view permission #49115 [CVE-2026-4630] Keycloak Authorization Services Protection API IDOR (Cross-Resource Server Access) #49116 [CVE-2026-37981] Broken Access Control in Account Resources User Lookup allows PII enumeration Enhancements #47728 Monitor backups for CNPG -

## Mintlify Security Event - November 2025

DevFeed: [Mintlify Security Event - November 2025](<https://devfeed.tech/articles/mintlify-security-event-november-2025-31113.md>)

Original publisher: [Read original article](<https://www.mintlify.com/blog/working-with-security-researchers-november-2025>)

Author: Han Wang

Published: 2025-12-18T00:00:00Z

Content type: article

Language: en

Sources: [Mintlify Blog](<https://devfeed.tech/sources/mintlify-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [XSS](<https://devfeed.tech/topics/xss.md>), [incident](<https://devfeed.tech/topics/incident.md>), [hosting](<https://devfeed.tech/topics/hosting.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [announcements](<https://devfeed.tech/tags/announcements.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [incident](<https://devfeed.tech/tags/incident.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

Mintlify describes how security researchers identified a cross-domain XSS vulnerability in its static asset hosting in November 2025. The company deployed a fix within 45 minutes, purged caches, audited hosted assets, notified potentially affected customers, and collaborated with the researchers on testing and further security improvements.

### Source excerpt

How a week-long collaboration with security researchers helped us identify and fix vulnerabilities, making Mintlify more secure for everyone.

## exploits.club Weekly Newsletter 81 - Safari Spills, SonicWall Overflows, Pixel 8 KGDB, and More

DevFeed: [exploits.club Weekly Newsletter 81 - Safari Spills, SonicWall Overflows, Pixel 8 KGDB, and More](<https://devfeed.tech/articles/exploits-club-weekly-newsletter-81-safari-spills-sonicwall-overflows-pixel-8-kgdb-and-more-32638.md>)

Original publisher: [Read original article](<https://blog.exploits.club/exploits-club-weekly-newsletter-81-safari-spills-sonicwall-overflows-pixel-8-kgdb-and-more/>)

Author: exploits.club

Published: 2025-08-07T15:00:14Z

Content type: news

Language: en

Sources: [exploits.club](<https://devfeed.tech/sources/exploits-club.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [browsers](<https://devfeed.tech/topics/browsers.md>), [Compiler](<https://devfeed.tech/topics/compiler.md>), [heap overflow](<https://devfeed.tech/topics/heap-overflow.md>), [XSS](<https://devfeed.tech/topics/xss.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [Android](<https://devfeed.tech/topics/android.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [debugging](<https://devfeed.tech/topics/debugging.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>)

Tags: [browsers](<https://devfeed.tech/tags/browsers.md>), [compiler](<https://devfeed.tech/tags/compiler.md>), [cve](<https://devfeed.tech/tags/cve.md>), [debug](<https://devfeed.tech/tags/debug.md>), [debugging](<https://devfeed.tech/tags/debugging.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [heap-overflow](<https://devfeed.tech/tags/heap-overflow.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [newsletter](<https://devfeed.tech/tags/newsletter.md>), [weekly](<https://devfeed.tech/tags/weekly.md>)

### AI overview

The 81st exploits.club weekly newsletter rounds up security research and developer-oriented write-ups covering a Safari vulnerability, SonicWall SMA100 stack and heap overflows plus reflected XSS, and kernel debugging over a serial connection on a Pixel 8. It also mentions Project Zero disclosure guidelines, Pwn2Own Ireland, Phrack print copies, and an Interrupt Labs release.

### Source excerpt

Your friendly neighborhood editor will BE at HACKER SUMMER CAMP! Just look out for a beard, black t-shirt, and backpack...you won't miss me. Annnnnnnyways 👇 In Case You Missed It... Print Copies Of Phrack - Snag yours if you'll be at one of the events!

## Common Web Application Security Vulnerabilities (OWASP Top 10)

DevFeed: [Common Web Application Security Vulnerabilities (OWASP Top 10)](<https://devfeed.tech/articles/common-web-application-security-vulnerabilities-owasp-top-10-28413.md>)

Original publisher: [Read original article](<https://banes.dev/common-web-application-security-vulnerabilities-owasp-top-10/>)

Author: admin

Published: 2024-05-07T15:00:43Z

Content type: article

Language: en

Sources: [Posts on Chris Banes](<https://devfeed.tech/sources/posts-on-chris-banes.md>)

Topics: [web applications](<https://devfeed.tech/topics/web-applications.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [XSS](<https://devfeed.tech/topics/xss.md>), [SQL](<https://devfeed.tech/topics/sql.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Databases](<https://devfeed.tech/topics/databases.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [browser](<https://devfeed.tech/tags/browser.md>), [database](<https://devfeed.tech/tags/database.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [sql](<https://devfeed.tech/tags/sql.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

This introductory article explains OWASP and its Top 10 list of common web application security problems. The supplied text specifically discusses injection attacks, SQL injection, cross-site scripting, broken authentication, and exposure of sensitive data.

### Source excerpt

You spent months creating the best online store. You have great products, a nice looking website, and you're all set to make sales. But did you think about security? Did you know that hackers can easily break into websites that aren't protected? They could steal your customers' credit card details, mess up your store, or [...]

## Preventing XSS Attacks

DevFeed: [Preventing XSS Attacks](<https://devfeed.tech/articles/preventing-xss-attacks-29979.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/xss-attacks/>)

Author: info@goteleport.com (Russell Jones)

Published: 2021-02-23T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [XSS](<https://devfeed.tech/topics/xss.md>), [Security](<https://devfeed.tech/topics/security.md>), [browser](<https://devfeed.tech/topics/browser.md>), [Document Object Model (DOM)](<https://devfeed.tech/topics/dom.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [API](<https://devfeed.tech/topics/api.md>), [Cookies](<https://devfeed.tech/topics/cookies.md>), [HTML](<https://devfeed.tech/topics/html.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [browser](<https://devfeed.tech/tags/browser.md>), [code](<https://devfeed.tech/tags/code.md>), [cookies](<https://devfeed.tech/tags/cookies.md>), [html](<https://devfeed.tech/tags/html.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [security](<https://devfeed.tech/tags/security.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

This article explains cross-site scripting (XSS), how browser security mechanisms such as the Same-Origin policy, the DOM, JavaScript, and cookies shape web isolation, and why dynamically generated sites that mix code and user-controlled data are difficult to secure. It introduces XSS attack examples and mitigation concepts.

### Source excerpt

Understanding Cross-Site Scripting (XSS) and Its Mitigations.

## Learning Angular: Conditionally add styles to an element

DevFeed: [Learning Angular: Conditionally add styles to an element](<https://devfeed.tech/articles/learning-angular-conditionally-add-styles-to-an-element-21286.md>)

Original publisher: [Read original article](<https://juri.dev/blog/2016/01/learning-ng2-dynamic-styles/>)

Published: 2016-01-24T00:00:00Z

Content type: tutorial

Language: en

Sources: [Juri Strumpflohner](<https://devfeed.tech/sources/juri-strumpflohner.md>)

Topics: [Angular](<https://devfeed.tech/topics/angular.md>), [CSS](<https://devfeed.tech/topics/css.md>), [Document Object Model (DOM)](<https://devfeed.tech/topics/dom.md>), [Sanitization](<https://devfeed.tech/topics/sanitization.md>), [Security](<https://devfeed.tech/topics/security.md>), [XSS](<https://devfeed.tech/topics/xss.md>)

Tags: [angular](<https://devfeed.tech/tags/angular.md>), [code](<https://devfeed.tech/tags/code.md>), [components](<https://devfeed.tech/tags/components.md>), [css](<https://devfeed.tech/tags/css.md>), [egghead](<https://devfeed.tech/tags/egghead.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [learning](<https://devfeed.tech/tags/learning.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

This tutorial explains several ways to conditionally apply styles and CSS classes to DOM elements in Angular version 2 or later. It covers direct style binding, style sanitization for dynamically supplied background images, NgClass, single-class syntax, and applying classes to components.

### Source excerpt

Lorem ipsum dolor sit amet

## Converting a Project to XHP

DevFeed: [Converting a Project to XHP](<https://devfeed.tech/articles/converting-a-project-to-xhp-22044.md>)

Original publisher: [Read original article](<https://codebeforethehorse.tumblr.com/post/87306947716>)

Author: Codebeforethehorse

Published: 2014-05-30T16:15:00Z

Content type: tutorial

Language: en

Sources: [Stefan Parker](<https://devfeed.tech/sources/stefan-parker.md>)

Topics: [Refactoring](<https://devfeed.tech/topics/refactoring.md>), [XSS](<https://devfeed.tech/topics/xss.md>), [Code](<https://devfeed.tech/topics/code.md>), [HTML](<https://devfeed.tech/topics/html.md>)

Tags: [code](<https://devfeed.tech/tags/code.md>), [html](<https://devfeed.tech/tags/html.md>), [refactoring](<https://devfeed.tech/tags/refactoring.md>), [xhp](<https://devfeed.tech/tags/xhp.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

This tutorial explains how to migrate a project from HTML strings to XHP by wrapping selected raw HTML in marker objects and modifying XHP's child rendering and validation internals. It also argues against using automatic regex conversion because it could perpetuate HTML-string usage.

### Source excerpt

Unless you're starting from scratch, using XHP is most likely going to take some refactoring of old HTML-as-string code. The problem is that because of XHP's auto-escaping to prevent XSS holes, you can't include strings of HTML as children into XHP elements. Fortunately there's something you can do to allow XHP to ignore certain strings and return them directly as HTML. This is essentially what Facebook had to do when we started converting our entire codebase into XHP in 2009. First off, you'll need a marker for strings that should be ignored by XHP. The best way to do this is to create an object that holds the strings and you can easily do instanceof checks on it. Let's call this object HTML (protip: objects and classes exist in different contexts, so they can have the same name without problem). class HTML { private $htmlString; public function __construct($htmlString) { $this->htmlString = $htmlString; } public function getRawHTML() { return $this->htmlString; } } function HTML($htmlString) { return new HTML($htmlString); } Now we'll need to adjust XHP's internals in two places to check for the existence of HTML objects: when rendering children and when validating children. The first location will be inside :xhp:renderChild(). The method looks like this: final protected static function renderChild($child) { if ($child instanceof :xhp) { return $child->__toString(); } else if (is_array($child)) { throw new XHPRenderArrayException('Can not render array!'); } else { return htmlspecialchars((string)$child); } } You'll need to add a check into this block for your HTML instances. Best place is right after your check for :xhp, since that should be the most common. final protected static function renderChild($child) { if ($child instanceof :xhp) { return $child->__toString(); } else if ($child instanceof HTML) { return $child->getRawHTML(); } else if (is_array($child)) { throw new XHPRenderArrayException('Can not render array!'); } else { return htmlspecialchars((string)

## The Difference Between :x:element and :x:primitive

DevFeed: [The Difference Between :x:element and :x:primitive](<https://devfeed.tech/articles/the-difference-between-x-element-and-x-primitive-22031.md>)

Original publisher: [Read original article](<https://codebeforethehorse.tumblr.com/post/35419887698>)

Author: Codebeforethehorse

Published: 2012-11-10T18:16:00Z

Content type: tutorial

Language: en

Sources: [Stefan Parker](<https://devfeed.tech/sources/stefan-parker.md>)

Topics: [XSS](<https://devfeed.tech/topics/xss.md>), [Sanitization](<https://devfeed.tech/topics/sanitization.md>), [HTML](<https://devfeed.tech/topics/html.md>), [JSON](<https://devfeed.tech/topics/json.md>), [html elements](<https://devfeed.tech/topics/html-elements.md>), [Ajax](<https://devfeed.tech/topics/ajax.md>)

Tags: [foreach](<https://devfeed.tech/tags/foreach.md>), [function](<https://devfeed.tech/tags/function.md>), [html](<https://devfeed.tech/tags/html.md>), [html-elements](<https://devfeed.tech/tags/html-elements.md>), [json](<https://devfeed.tech/tags/json.md>), [payload](<https://devfeed.tech/tags/payload.md>), [protection](<https://devfeed.tech/tags/protection.md>), [render](<https://devfeed.tech/tags/render.md>), [rest](<https://devfeed.tech/tags/rest.md>), [xhp](<https://devfeed.tech/tags/xhp.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

This article explains when to use :x:element versus :x:primitive in XHP. It recommends :x:element for most cases because its render() method produces more XHP and supports recursive rendering, while :x:primitive ultimately stringifies the result. It identifies custom HTML nodes and non-HTML output such as JSON AJAX responses as the main reasons to use :x:primitive.

### Source excerpt

I was recently asked to clarify the differences between :x:element and :x:primitive, and when to use each one. It's actually pretty simple; the basic rule of thumb is this: always use :x:element. If you're only doing simple things in XHP you can stop reading now, but for the rest of you I'll get into the rare instances where you might use :x:primitive. First, the main difference. :x:element implements the render() method, which returns more XHP while :x:primitive implements to stringify() method, which returns a string. When you echo XHP to the page, it recursively calls render() on itself until it returns an :x:primitive. It will continue to do this to any children of an :x:primitive as well. Once the entire tree is just :x:primitives (usually meaning just HTML nodes) it stringify()s it. So why the difference? The big reason was that we can put XSS protection in all HTML elements and so long as you just return HTML nodes you'll never have to worry about input sanitization again. There are two cases where you would want to create an :x:primitive though. The first being if you wanted to create a custom HTML node. Let's say you wanted to create a <foo> tag for your own purposes. All you would need to do is extend :xhp:html-element (which extends :x:primitive) and define its tag name. class :foo extends :xhp:html-element { protected $tagname = 'foo'; } Pretty simple. You could define custom attributes and children restrictions too if you so desired. The other reason you would extend :x:primitive is if you wanted to return something other than HTML. Consider an AJAX response that returns a JSON object. You might construct an object that behaves like this: class :ajax:response extends :x:primitive { attribute array payload; attribute array errors; protected function stringify() { $html = ''; foreach ($this->getChildren() as $child) { $html .= :x:base::renderChild($child); } $response = array( 'payload' => $this->getAttribute('payload'), 'errors' => $this->getAttribute('e

## XSS Protection: Who Is Responsible?

DevFeed: [XSS Protection: Who Is Responsible?](<https://devfeed.tech/articles/xss-protection-who-s-responsibility-31951.md>)

Original publisher: [Read original article](<https://tech.finn.no2011/04/08/xss-protection-whos-responsibility/>)

Author: mick

Published: 2011-04-08T07:09:39Z

Content type: opinion

Language: en

Sources: [Finn.no](<https://devfeed.tech/sources/finn-no.md>)

Topics: [XSS](<https://devfeed.tech/topics/xss.md>), [Security](<https://devfeed.tech/topics/security.md>), [Front end](<https://devfeed.tech/topics/frontend.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [backend](<https://devfeed.tech/tags/backend.md>), [cms](<https://devfeed.tech/tags/cms.md>), [cookies](<https://devfeed.tech/tags/cookies.md>), [databases](<https://devfeed.tech/tags/databases.md>), [front-end](<https://devfeed.tech/tags/front-end.md>), [legacy](<https://devfeed.tech/tags/legacy.md>), [security](<https://devfeed.tech/tags/security.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

The article examines whether XSS protection in multi-tier applications should belong to a dedicated security team or be shared across developers. It contrasts new applications, where input may be cleaned before storage, with legacy applications whose existing backend data can require extensive front-end protection, and illustrates the issue with an advertisement service and view template.

### Source excerpt

In a multi-tier application who can be responsible for XSS protection? Must security belong to a dedicated team...or can it be a shared responsibility? Today XSS protection is typically tackled by front end developers. Let's challenge the status quo. New Applications vs Legacy Applications For protection against Stored XSS many applications have the luxury of ensuring any text input from the user, or from a CMS system, is made clean and safe before being written to database. Given a clean database the only XSS protection required is around request values, for example values from url parameters, cookies, and form data. But some applications, especially legacy applications, are in a different boat. Databases typically have lots of existing data in many different formats and tables so it's often no longer feasible to focus on protecting data on its way into the system. In this situation it is the front end developers that pay the price for the poor quality of backend data and are are left to protect everything. This often results in a napalm-the-whole-forest style of xss protection where every single variable written out in the front end templates goes through some equivalent of <c:out value="${someText}"/> This makes sense but... if you don't have control is your only option to be so paranoid? A Messed up World To illustrate the problem let's create a simple example by defining the following service interface AdvertisementService{ Advertisement getAdvertisement(long id); } interface Advertisement{ /** returns plain text title */ String getTitle(); /** return description, which may contain html if isHtmlEnabled() returns true */ String getDescription(); /** indicates the description is html */ boolean isDescriptionHtml(); } The web application, having already fetched an advertisement in the control tier, somewhere would have a view template looking something like <div> <h1><c:out value="${advertisement.title}"/></h1> <p> <c:out value="${advertisement.description}" escapeXm