Stored XSS, also known as persistent XSS, is the more damaging of the two. It occurs when a malicious script is injected directly into a vulnerable web application. Information Theft: One of the most concerning consequences of stored XSS is the potential for information theft. Attackers can leverage the vulnerability to steal sensitive user data, such as login credentials, personal information, or financial details.