OWASP Top 10:2025 OWASPTOP10-3: A03:2025 Injection Including Cross-Site Scripting
Address OWASP Top 10 A03 Injection per OWASP Top 10:2025. Injection occurs when untrusted data is sent to an interpreter as part of a command or query enabling SQL injection + NoSQL injection + LDAP injection + OS command injection + ORM injection + XML/XPath injection + Server-Side Template Injection (SSTI) + Cross-Site Scripting (XSS) + and other injection variants. Mitigations include (a) validate + sanitise + escape input at trust boundaries + (b) use parameterised queries + prepared statements + ORM safe-query APIs against SQL/NoSQL injection + (c) use context-appropriate output encoding against XSS (HTML + URL + JS + CSS encoding) + (d) implement Content Security Policy + Trusted Types + (e) validate file uploads (type + size + content + scanning) + (f) protect against XXE + deserialisation + template injection via safe parser configuration.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 45 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
GS1-EPCIS-CBV-EventBasedDataSharing GS1 EPCIS (Electronic Product Code Information Services) and CBV (Core Business Vocabulary) Event-Based Data Sharing
IATF16949-Clause8-Supplier-QMS-Development-Externally-Provided IATF 16949 Clause 8 Supplier - Control of Externally Provided Processes + Type and Extent + Supplier QMS Development