Stored Cross-Site Scripting (XSS) occurs when an attacker uploads or injects a malicious script onto a target server (such as in a comment section). The script then executes inside the browser of any user who retrieves and reads that content, attacking the client side.