Cross-Site Scripting, better known as **XSS** in the cybersecurity community, is classified as an *injection attack* where **malicious JavaScript gets injected into a web application with the intention of being executed by other users**. - [[Reflected XSS]] - [[Stored XSS]] - [[DOM based XSS]] - [[Blind XSS]]