CWE-79 Cross-Site Scripting
Coverage: 88 rules in the SiteShadow rule registry target this CWE (registry v2.0.0). Regex 67Other-pattern 21 Also: Taint and heuristic analyzers may also detect related flows (see coverage for the authoritative list) Registry tagging shows intent, for sample-level behaviour and benchmarked gaps see known gaps.
What this means
SiteShadow found a pattern where untrusted input may be rendered as HTML or script.
Why it matters
- Attackers can run arbitrary JavaScript in victims' browsers.
- This can steal sessions, perform actions as the user, or silently change what users see.
Safer examples
1) Escape by default, only allow HTML when necessary
Use templating systems that escape output by default, and avoid "raw" rendering modes.
2) Sanitize when rendering user-provided HTML
el.innerHTML = DOMPurify.sanitize(userHtml);
3) Add defense-in-depth with CSP
Use Content Security Policy to reduce impact if an XSS slips through.
How SiteShadow detects it (high level)
- Finds common XSS sinks and checks whether their inputs appear user-controlled.
- Applies context heuristics to avoid flagging safe patterns (escaped output/sanitizers).
References
- CWE-79: https://cwe.mitre.org/data/definitions/79.html
---
← Back to Vulnerability Library
Catch this in your code with SiteShadow.
Every released SiteShadow scanner is free, including full project analysis, reports, patterns, dashboard access, and configured organization SSO.