I believe that standard CSS, parsed in a standard way, is safe. However, through various non-standard extensions, CSS is unsafe .
This is not just CSS, which is unsafe due to the fact that some browsers ignore RFC 2616 and sniff the content type rather than respect the title Content-Type, some browsers can be bypassed to embed JavaScript hidden in static image files.
, , .
, , , cookie www. , , , .