OWASP has published a very well written XSS cheat sheet.
BSIMM CWE/SANS Top 25 entity expansion Fortify IO Chokepoints J2EE JSTL Maturity Module OWASP Top 10 Process regex Static Analysis Struts Trust validation Xerces XML XSS