Home > Managing Application Security > About Cross-Site Scripting ... > Protecting Report Regions
The Application Express engine escapes data rendered in the body of a report. References to session state in report headings and messages are fetched from session state using the smart escaping rules so that the values of safe item types are not escaped and the values of other item types are escaped.