Cross-site scripting lets YOUR browser run code written by a stranger — inside the site you already trust. One input field, one missing filter, and sessions, passwords, and accounts bleed out. This guide breaks all three XSS flavors, the payloads, and the fix, explained so a kid could repeat it...