# How to stop xss payload?

**URL:** https://discourse.getcockpit.com/t/how-to-stop-xss-payload/3262
**Category:** Support
**Created:** [October 28, 2025, 5:01am UTC](https://discourse.getcockpit.com/t/how-to-stop-xss-payload/3262 "2025-10-28T05:01:44Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![HelloDolly](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/hellodolly/32/1181_2.png) [@HelloDolly](https://discourse.getcockpit.com/u/HelloDolly)
#### Post date: [October 28, 2025, 5:01am UTC](https://discourse.getcockpit.com/t/how-to-stop-xss-payload/3262/1 "2025-10-28T05:01:44Z")

</div>

```auto
<script>alert(‘XSS’)< /script>

```

these gets gets stored in database. how to deal with these?

---

<div class="post-metadata">

### Author: ![artur](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/artur/32/4_2.png) [@artur](https://discourse.getcockpit.com/u/artur)
#### Post date: [October 30, 2025, 1:24pm UTC](https://discourse.getcockpit.com/t/how-to-stop-xss-payload/3262/2 "2025-10-30T13:24:58Z")

</div>

Do a sanatize the content before output

---

<div class="post-metadata">

### Author: ![HelloDolly](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/hellodolly/32/1181_2.png) [@HelloDolly](https://discourse.getcockpit.com/u/HelloDolly)
#### Post date: [November 11, 2025, 2:37am UTC](https://discourse.getcockpit.com/t/how-to-stop-xss-payload/3262/3 "2025-11-11T02:37:07Z")

</div>

say provided we want to clean the data prior saving, where should i start tinkering? a little headstart would be helpful.
