This content is also available in german
Hacking a React app to expose real-world threats like XSS and injection — and how to fix them.React Miami 2026
React Norway 2026
Abstract
React has your back, at least on paper. With almost no CVEs in recent years, React Core stands out as one of the most secure frontend frameworks available. But security isn't automatic. In this session, Ramona will shine a light onto a React application to expose real-world threats like XSS, injection attacks, and subtle frontend vulnerabilities. You'll learn where React protects you by default, where it doesn't, and how to become the final line of defense for your users.
Slides
You can find the slides of the talk on speakerdeck
Slides(opens in a new tab)