Glossary Entry
What is Cross-Site Scripting?
What Cross-Site Scripting actually means, buzzwords removed — with the example that makes it land.
The short answer
With XSS, an attacker's script ends up inside pages other people load, taking sessions, defacing content or redirecting visitors, and all of it under your site's name.
The rest of the page opens it up — the mechanics, why a site owner should care, and one concrete example of it at work.
By the Hosting & Domains team · Reviewed 18 August 2026
0
Jargon left undefined
100+
Entries, all cross-linked
Real
Working examples
Free
To read, always
The target is a page that echoes input back unescaped, so a comment or a URL parameter renders as running script rather than as plain text. In code the answer is escaping on output; in practice, WAF rules and sensible cookie flags such as HttpOnly limit what any successful attempt can achieve.
Exactly as with injection, this reaches an owner's doorstep through somebody else's component. It is the vulnerable plugin doing the echoing, and it is your visitors who carry the exposure.
The everyday parallel
Graffiti that issues orders. Somebody writes on the public noticeboard, and everybody who reads it afterwards finds themselves obeying it without ever deciding to.
Carry that picture with you and most documentation on the topic loses its mystery on a first read.
Where it touches your own site
The victims are your visitors and your pages are the delivery mechanism, which adds up to stolen sessions and scam redirects trading on your domain's good name. Defence comes down to the familiar three: components kept current, a WAF standing in front, and a platform carrying as little as it can.
Nobody expects you to work at this layer daily. The aim is recognising it when it explains something — and that moment is exactly when this page pays for itself.
How it turns up day to day
Given a hand-crafted comment, a weak plugin renders it as running script, and the script takes session cookies. The WAF catches the probe's pattern, and the patch released that week seals the echo it was exploiting.
Entirely unremarkable once you have seen it — which is the point: most hosting ideas are plain machinery behind an intimidating label.
Where it sits inside your own account
You will meet it in the control panel and now and then in a support thread, usually already set correctly. If this one landed, the natural follow-ups are SQL Injection, WAF, HTTPS and Plugin.
NVMe storage and LiteSpeed caching sit under every tier, the smallest plan included — that is the floor here, not an upgrade.

A jargon buster from the people who answer the tickets
Sooner or later every confusing hosting term turns into a support ticket, so we defined the hundred commonest ones properly — once, in the same plain English we use with customers.
Order an annual plan and the first year of the name's registration is on us.
- 100+ entries, plain English all the way
- Ordinary analogies, working examples
- Neighbouring ideas linked together
- Written by our own support engineers
Why Hosting & Domains
Standard on every plan
Cross-wired entries
Related terms point at each other, so one lookup compounds into working knowledge.
Clear about how deep to go
Most of these are recognise-level rather than operate-level, and every entry says which it is.
Analogies that hold
Every concept comes with a mental model that returns exactly when you need it.
Jargon-free by design
Definitions written for people who run sites, not for other sysadmins — translation rather than restatement.
Stakes made explicit
More than what a thing is: the moments it turns out to be the answer to a problem you have.
This term, properly landed
Cross-Site Scripting defined, pictured by analogy and located in your own panel — recognise-level after a single read.
Quick Start
Order placed to site online
- 1
Find it in your own account
Open the control panel and find where this idea sits — a definition turns into understanding the moment it attaches to your own site.
- 2
Check the defaults as they stand
The platform ships sensible defaults for this — check rather than assume, and your setup becomes something you know instead of hope.
- 3
Chase the neighbouring terms
Hosting terms travel in groups — SQL Injection, WAF and HTTPS finish this one's picture, each a two-minute read away.
Built In
Fitted to every plan
- cPanel, which is what most of the industry already runs
- Money back within 30 days on hosting plans, 7 on reseller
- WebP image optimisation built in, at no extra charge
- Your existing site brought across by our engineers, at no charge
- Webmail in the browser plus IMAP, POP and SMTP for any client
- Spam and virus screening on every mailbox by default
- WordPress and 400+ further applications installed in one click
- 99.9% uptime as the target, watched around the clock
- NVMe SSD storage on every tier, not only the dear ones
- A daily copy, with restores you run yourself from the panel
Frequently Asked
The questions that come up most
Does HTTPS protect against XSS?
It does not, and the confusion is common. HTTPS secures the journey, whereas XSS runs inside the page after arrival and works exactly as well over an encrypted connection. A padlock vouches for the delivery alone and says nothing about what the page's own scripts then do.
What can a site owner do about XSS?
Update your components, since that is where these flaws live. Choose hosting with a WAF built in, so attempts are pattern-blocked on the way through. Keep the plugin list short as well, since each addition adds surface. Escaping discipline belongs to framework and plugin authors, while keeping up with their fixes belongs to you.
Can I transfer in a name I already own?
Yes, and it is routine. Unlock the name at your current registrar, take the auth code, and start the transfer from your client area. Whatever registration time remains carries over, and DNS keeps resolving the whole way through.
What does round-the-clock support actually cover?
A reply from a person at any hour, covering the practical jobs: setting up a mailbox, a DNS record, a WordPress fault, a restore. Not 'server is up, closing ticket'. Put a hard question to us before you buy — the answer is a fair sample of what follows.
Keep reading
HTTPS
Wrap ordinary HTTP in an encrypted connection and you have HTTPS, the web's standard transport, which keeps…
WAF (Web Application Firewall)
A WAF inspects incoming web requests for attack patterns such as SQL injection, injected scripts and probes…
How to Test Your Website Speed
The way it is really done, in order, with the usual mistake pointed out.
Domain Names
Find, register and transfer names — year one free with annual hosting.
Web Hosting
cPanel hosting on NVMe drives — SSL, the migration and year one of the name all included.
Changing hosts? Run through our checklist first.
A plain order of work for a move nobody visiting will notice: which files go over first, how to carry the mail across without losing a message, when exactly to repoint DNS, and the two mistakes behind nearly every outage we are asked to rescue.
Your site has earned better hosting.
NVMe hosting with SSL and the migration included, people answering at any hour, and a price that stays where it was.
View Domain Names plans