What MITRE CAPEC-63: Cross-Site Scripting (XSS) (Attack Pattern - Very High Severity) requires
MITRE CAPEC-63 (Cross-Site Scripting) is an attack pattern in which an adversary embeds malicious scripts in content that will be served to web browsers; the target client-side browser executes the script with the users privilege level. Likelihood of attack: High. Typical severity: Very High. Maps to CWE-79 (Improper Neutralization of Input During Web Page Generation) and CWE-20 (Improper Input Validation). Compliance: OWASP ASVS V5.3 (output encoding), OWASP Top 10 A03:2021 Injection, PCI DSS v4.0 Requirement 6.2.4, NIST SP 800-53 SI-10, ISO/IEC 27001 A.8.28.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/63.html
SHA-256 integrity: daa03ebe377263b7adedbcb9a0e4e3b505772204a25b3a2d88896a5ba913e2c0
Primary Citations — 8 traced to source
- MITRE CAPEC-63: Cross-Site Scripting (https://capec.mitre.org/data/definitions/63.html)
- CWE-79: Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.