The page is trusted; anything that lands on it inherits that trust. If a comment, a profile field or a URL parameter reaches the HTML unescaped, the attacker's script runs in every visitor's browser — reading session tokens, keylogging, acting as the user. Stored, reflected and DOM-based are the three shapes it takes.
The defence is escaping by default — every framework's templating does it unless you opt out with dangerously-set-anything — plus a content security policy as the second layer. If user content can ever touch the DOM raw, it eventually will.
Related terms
CSRF
Cross-site request forgery — tricking a logged-in browser into sending a request the user never meant, riding on their cookies.
Content Security Policy
A header that whitelists where a page's scripts, styles, images and connections may come from — the second wall that stops XSS even when injection happens.
OWASP Top 10
The long-standing community list of the most critical web application security risks, revised every few years.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
