# XSS (Cross Site Scripting) **Web Content-Types to XSS** The following content types can execute XSS in all browsers: * `text/html` * `application/xhtml+xml` * `application/xml` * `text/xml` * `image/svg+xml` * `text/plain` (?? not in the list but I think I saw this in a CTF) * `application/rss+xml` (off) * `application/atom+xml` (off) In other browsers other Content-Types can be used to execute arbitrary JS, check: https://github.com/BlackFan/content-type-research/blob/master/XSS.md ## XSS Tips * If your input is placed in the following tags, you must first exit these tags: * `