Escape User HTML
Escape User HTML: free step-by-step lesson with examples, common mistakes, and interview tips — part of jQuery Tutorial on Toolliyo Academy.
On this page
jQuery Tutorial · Lesson 66 of 100
Escape User HTML
Setup & DOM ✓ → Events Effects AJAX ✓ → Perf & Integrate → Ship & Projects
Perf & Integrate · 3 — Harden · ~10 min · Performance and Security
What is this?
Never inject raw user strings with .html(). Use .text() or a vetted escape/sanitize step before inserting markup.
Why should you care?
XSS in QueryVerse search boxes and comments remains a top legacy bug class.
See it live — copy this example
Examples include the jQuery 3.7 CDN. Paste into an HTML file or use Run Example to preview.
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>QueryVerse</title>
<style>
body { font-family: system-ui, sans-serif; margin: 1.25rem; }
.box { padding: .75rem; border: 1px solid #ccc; border-radius: 8px; margin: .5rem 0; }
.muted { color: #666; }
button { margin-right: .35rem; margin-top: .35rem; }
input, select, textarea { margin: .25rem 0; }
table { border-collapse: collapse; width: 100%; }
th, td { border: 1px solid #ddd; padding: .4rem .55rem; text-align: left; }
.hidden { display: none; }
.row-odd { background: #f7f7f7; }
.active { font-weight: 700; }
.toast { background: #111; color: #fff; padding: .5rem .75rem; border-radius: 6px; }
</style>
</head>
<body>
<input id="name" placeholder="Type anything" value="<img src=x onerror=alert(1)>">
<button type="button" id="safe">Render safe</button>
<button type="button" id="unsafe">Render unsafe (demo)</button>
<div id="out" class="box"></div>
<script src="https://code.jquery.com/jquery-3.7.1.min.js"></script>
<script>
$(function () {
$('#safe').on('click', function () {
$('#out').text($('#name').val());
});
$('#unsafe').on('click', function () {
// Demo only — do not ship this pattern
$('#out').html($('#name').val());
});
});
</script>
</body>
</html>
Run Example »
Edit the code below and click Run to see the result in Toolliyo’s live editor.
What happened?
- Safe path uses text.
- Unsafe path parses HTML/JS.
- If rich text is required, sanitize server-side and with a known library — not regex alone.
Practice next
- Try both buttons with the default payload.
- Clear the out box between tries.
- Discuss why text wins.
- Enable CSP in production later.
- Sanitize HTML emails before preview.
Remember
Untrusted → text. html is privileged. Review every .html( call.
Search echo XSS
A Shaadi.com support QueryVerse page echoes the agent’s query on results.
Outcome: text() prevents the onerror payload from running.
Interview prep for this lesson
Practice these questions aloud after reading—each links to a full structured answer.
Sign in to ask a question or upvote helpful answers.
No questions yet — be the first to ask!