Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up

HTML Entity Encoder & Decoder Studio

Convert reserved HTML characters, symbols, and Unicode strings into named, decimal, or hexadecimal entities and decode them safely.

0 chars

⚠️ 5 Fatal Traps in HTML Entities & XSS Defense Architecture

💥 1. The Incomplete 5-Character Sanitization Fallacy

Escaping only the five canonical characters (& < > " ') is insufficient to prevent Cross-Site Scripting (XSS) inside unquoted HTML attributes or JavaScript event handlers. Inside an unquoted attribute (<input value=${input}>), an attacker does not need quotes or angle brackets; a simple space or tab followed by onfocus=alert(1) autofocus achieves full script execution.

⚖️ 2. Double-Encoding Cascades (&amp;amp; Pollution)

When user input is encoded during database storage and subsequently re-encoded during template rendering, ampersands compound exponentially: &copy; becomes &amp;copy;, displaying literal &copy; code on screen instead of the copyright symbol. Applications should store unescaped canonical strings in the database and apply entity encoding exclusively at the final view rendering boundary.

🛡️ 3. Context Ineffectiveness in 'href' & 'src' URI Attributes

HTML entity encoding does NOT sanitize URLs. If an attacker inputs javascript:alert(document.cookie) and you entity-encode it as <a link-url="&#106;avascript:alert(1)">, modern web browsers decode the HTML entities inside URI attributes BEFORE executing the link, resulting in instant XSS. URIs require strict protocol whitelisting (http://, https://).

🔍 4. DOM-Based XSS via 'innerHTML' Entity Decoding

A pervasive JavaScript antipattern decodes HTML entities by creating an off-screen element and setting el.innerHTML = input followed by reading el.textContent. If the input contains <img src=x onerror=alert(1)>, setting innerHTML immediately fires the onerror event in browser memory before the element is even attached to the DOM.

🚀 5. XML / SVG Parser Abort on HTML Named Entities

While HTML5 recognizes over 2,000 named entities (e.g. &nbsp;, &euro;, &mdash;), strict XML, XHTML, and SVG engines only natively recognize five: &quot; &amp; &apos; &lt; &gt;. Injecting &nbsp; into an SVG or RSS feed causes XML parsers to abort with fatal entity not defined parsing errors.

Click Me & Win $1,000! '; document.getElementById('ent-in').value = payload; entityTransform('named'); }; window.copyHtmlEntities = function() { var out = document.getElementById('ent-out') ? document.getElementById('ent-out').value : ''; if (!out) { entityTransform('named'); out = document.getElementById('ent-out').value; } navigator.clipboard.writeText(out).then(function() { var btn = document.getElementById('btnCopyHtmlEntities'); if (btn) { var orig = btn.innerHTML; btn.innerHTML = '✓ HTML Entities Copied!'; btn.style.borderColor = '#10b981'; setTimeout(function() { btn.innerHTML = orig; btn.style.borderColor = 'var(--border)'; }, 2200); } }); }; document.addEventListener('DOMContentLoaded', function() { var inp = document.getElementById('ent-in'); if (inp && inp.value) entityTransform('named'); });
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement