All fixes

Add a Content-Security-Policy header

headers-csp

A Content-Security-Policy tells the browser which scripts it is allowed to run, so markup an attacker manages to inject never executes.

Cloudflare

  1. 1 Go to Rules > Transform Rules > Modify Response Header
  2. 2 Create a rule that sets Content-Security-Policy to the desired value
  3. 3 Deploy the rule
Header name: Content-Security-Policy
Value: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'
Cloudflare docs

Does your app still have this?

Scan your domain