What is XSS in a frontend interview?
PICTURE THIS: BROWSER VS ATTACKER
Simple meaning
Cross-site scripting is when attacker HTML or JavaScript runs in your users' browsers, usually through unsanitized output.
WHY — Security instead of guessing?
Why interviewers care about Security:
who only read docs from people who shipped.
and tied to Frontend work.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens step by step?
Before you speak the answer, walk the interviewer through these steps:
- 1Cross-site scripting is when
attacker HTML or JavaScript runs in your users' browsers, usually through unsanitized output.
- 2React escaping text children
already blocks a lot of it.
- 3Danger is innerHTML, markdown
renderers, and urls in href that start with javascript.
- 4Give an example
One tiny concrete case you can say aloud.
- 5Common mistake
What juniors usually get wrong.
- 6Close
When you pick this over the alternative.
EXAMPLE — See it in action
Here's a short line you can speak, broken into clear beats:
Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.
Key takeaway
Cross-site scripting is when attacker HTML or JavaScript runs in your users' browsers, usually through unsanitized output. React escaping text children already blocks a lot of it.