Content that is not actually created by the host site, but is developed, purchased or licensed from a third party. A concern associated with this content is that it can contain malicious code that is then unwittingly incorporated into the organization’s own website source code. For example, cross-site scripting (XSS) attacks attempt to take advantage of the trust that users have for a given site.
Reference(s) in IAPP Certification Textbooks: F129
Associated term(s): XSS