Of all the vulnerabilities plaguing modern applications, Cross-Site Scripting (XSS) is one of the oldest and most persistent.
Despite the fact that it has been a known threat for over two decades, XSS continues to appear from old systems to the new, cloud-native architectures.
See also: Web Application Security: SQL Injection, XSS, CSRF and WAF

The Microsoft Security Response Center (MSRC) recently highlighted the persistent nature of this threat, revealing that it continues to receive a steady stream of XSS reports across its range of services and applications. In a recent report, the MSRC shared insights into the prevalence and impact of XSS vulnerabilities, highlighting that even with advanced security measures such as Content Security Policies (CSP) and secure-by-default libraries, the threat remains significant.
Since January 2024, the MSRC has mitigated more than 970 XSS incidents, demonstrating the ongoing effort required to address this category of vulnerabilities. Between July 2024 and July 2025, XSS flaws accounted for 15% of all “Important” or “Critical” security incidents handled by the MSRC. During that time, the center addressed 265 specific XSS incidents, with 263 rated Important and two rated Critical. In recognition of the security researchers who discovered these vulnerabilities, Microsoft has awarded a total of $912,300 in XSS vulnerability bounties. The highest bounty for a high-impact XSS attack, such as one involving token theft or zero-click exploitation, was $20,000.
These vulnerabilities were not limited to a single product but were reported across a wide range of major Microsoft services. Microsoft Copilot, Microsoft 365, Dynamics 365, Microsoft Identity, Microsoft Azure , and Xbox all received XSS submissions. The reports, which came from both internal and external researchers, often included methods to bypass sanitization logic and exploit behaviors in modern web frameworks.
See also: Was the administrator of the hacking forum XSS.is arrested?

Not all XSS vulnerabilities carry the same risk. Microsoft prioritizes issues based on their actual impact on customers. Factors such as the likelihood of data exposure, the level of user interaction required for an exploit, and overall exploitability determine the severity of a vulnerability. MSRC uses a matrix that combines data classification with exploitation conditions to assign a severity rating.
Critical Severity: A zero-click XSS that compromises highly confidential data, such as session tokens or sensitive cookies, is rated as Critical.
Significant Severity: If an XSS requires some user interaction but can still expose confidential information, it is typically rated as Significant.
Moderate/Low Severity: XSS on public pages without exposure of sensitive data, or scenarios that require the user to perform the attack on themselves (self-XSS), are considered of lower severity.
Microsoft also clarified which types of XSS vulnerabilities are considered out of scope for servicing. These include self-XSS, which requires the user to manually paste a payload into the developer console of their browser, and vulnerabilities that run only in non-standard or outdated browsers such as Internet Explorer. Likewise, executing JavaScript within a restricted PDF environment usually does not meet the conditions unless it can escape to a more privileged environment.
See also: SonicWall patches critical SMA 100 vulnerability

To help security researchers, the MSRC provided a checklist for reporting XSS, emphasizing the need for clear, reproducible steps, a proof of concept that works without developer tools, and a detailed explanation of the security impact, such as token theft or session hijacking.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
