Application Express User's Guide > Managing Application Security > About Cross-Site Scripting ... > Protecting Form Items
| Protecting Form Items |  Previous |  Next | 
When form items, including hidden items, obtain their values during the generation of the form page to be sent to the browser, the resulting text is escaped before rendering. Some of the safe item types are exceptions to this rule in order to support the intended behavior of each display type.