Security · Comparison

XSS vs CSRF vs SQL injection

Three classic web attacks aimed at different layers. XSS runs an attacker's script inside your pages, CSRF borrows a visitor's signed-in browser, and SQL injection slips commands into your database queries.

3 options · 7 questions side by side · updated

CompareXSSCSRFSQL injection
What is attackedOther visitors' browsersA signed-in user's sessionThe database behind the app
Root causeUser text shown as HTML or scriptCookies sent on requests from other sitesUser input pasted into SQL text
Attacker gainsActs as the victim inside the pageOne unwanted action as the victimReads, changes or deletes data
Main defenceEscape output, sanitise HTMLSameSite cookies and CSRF tokensParameterised queries
Extra layersContent Security Policy, HttpOnly cookiesOrigin checks, no changes on GETLeast-privilege database user, a WAF
Framework helpReact, Vue and Svelte escape by defaultDjango, Laravel and Rails check tokensORMs and query builders use parameters
Classic mistakedangerouslySetInnerHTML with user inputChanging data on a GET requestBuilding SQL by joining strings

How to choose between XSS, CSRF and SQL injection

  • Treat XSS as an output problem: encode or sanitise everything shown to users, with a CSP as a safety net.
  • Treat CSRF as a cookie problem: SameSite cookies plus tokens or Origin checks on every request that changes data.
  • Treat SQL injection as a query problem: pass user input as parameters, never as part of the SQL text.

The options

More comparisons

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.