Cross-site scripting (XSS) TL;DR: Attacker JS executed in the victim’s authenticated context. Reflected / stored / DOM-based. Stub — to be filled in. What it is TODO Preconditions / where it applies TODO Technique TODO Detection and defence TODO References https://portswigger.net/web-security/cross-site-scripting