SiteShadow
Back to vulnerability library
Detected byCWE-aware static analysis

CWE-79 Cross-Site Scripting

Coverage: 88 rules in the SiteShadow rule registry target this CWE (registry v2.0.0). Regex 67Other-pattern 21 Also: Taint and heuristic analyzers may also detect related flows (see coverage for the authoritative list) Registry tagging shows intent, for sample-level behaviour and benchmarked gaps see known gaps.

What this means

SiteShadow found a pattern where untrusted input may be rendered as HTML or script.

Why it matters

Safer examples

1) Escape by default, only allow HTML when necessary

Use templating systems that escape output by default, and avoid "raw" rendering modes.

2) Sanitize when rendering user-provided HTML

el.innerHTML = DOMPurify.sanitize(userHtml);

3) Add defense-in-depth with CSP

Use Content Security Policy to reduce impact if an XSS slips through.

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Catch this in your code with SiteShadow.

Every released SiteShadow scanner is free, including full project analysis, reports, patterns, dashboard access, and configured organization SSO.