๐ก
CyberSecurity
Search...
Ctrl +โK
Penetration Testing
Certification Prep
Burp Suite Certified Practitioner
What to look for
By vulnerability type
XSS
Previous
Remediation
Next
Remediation
Last updated
2 years ago
Cheatsheets and How To's
Tools
Payloads
Cheatsheets and How To's
Tools
Payloads
What is cross-site scripting (XSS) and how to prevent it? | Web Security Academy
WebSecAcademy
GitHub - DanMcInerney/xsscrapy: XSS spider - 66/66 wavsep XSS detected
GitHub
XSS Filter Evasion - OWASP Cheat Sheet Series
GitHub - s0md3v/AwesomeXSS: Awesome XSS stuff
GitHub
XSS (Cross Site Scripting)
HackTricks
XSSI (Cross-Site Script Inclusion)
HackTricks
Cross-Site Scripting (XSS) Cheat Sheet - 2022 Edition | Web Security Academy
WebSecAcademy
Home ยท wisec/domxsswiki Wiki
GitHub
Excess XSS: A comprehensive tutorial on cross-site scripting
Stored XSS Via File Upload [SVG File Content]
Medium
Stored XSS Via File Upload [SVG File Content]
Medium
GitHub - LucaBongiorni/XSS.png: A XSS mind map ;)
GitHub
The 7 Main XSS Cases Everyone Should Know - Brute XSS
Brute XSS
DOM-based vulnerabilities | Web Security Academy
WebSecAcademy
Framing without iframes
PortSwigger Research
A Pentesterโs Guide to Cross-Site Scripting (XSS) | Cobalt
GitHub - hahwul/XSpear: Powerfull XSS Scanning and Parameter analysis tool&gem
GitHub
GitHub - hahwul/dalfox: ๐๐ฆ DalFox is an powerful open source XSS scanning tool and parameter analyzer, utility
GitHub
GitHub - t3l3machus/toxssin: A POST-XSS exploitation tool.
GitHub
GitHub - dwisiswant0/findom-xss: A fast DOM based XSS vulnerability scanner with simplicity.
GitHub
GitHub - ssl/ezXSS: ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
GitHub
GitHub - fcavallarin/domdig: DOM XSS scanner for Single Page Applications
GitHub
GitHub - rajeshmajumdar/BruteXSS: BruteXSS is a tool written in python simply to find XSS vulnerabilities in web application. This tool was originally developed by Shawar Khan in CLI. I just redesigned it and made it GUI for more convienience.
GitHub
GitHub - cure53/DOMPurify: DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
GitHub
GitHub - epsylon/xsser: Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.
GitHub
GitHub - SpiderMate/B-XSSRF: Toolkit to detect and keep track on Blind XSS, XXE & SSRF
GitHub
GitHub - kleiton0x00/XSScope: XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.
GitHub
GitHub - s0md3v/XSStrike: Most advanced XSS scanner.
GitHub
GitHub - s0md3v/JShell: JShell - Get a JavaScript shell with XSS.
GitHub
GitHub - menkrep1337/XSSCon: XSSCon: Simple XSS Scanner tool
GitHub
GitHub - LewisArdern/bXSS: bXSS is a utility which can be used by bug hunters and organizations to identify Blind Cross-Site Scripting.
GitHub
GitHub - Quitten/XSSor: XSSor is a semi-automatic reflected and persistent XSS detector extension for Burp Suite. The tool was written in Python by Barak Tawily, an application security expert. XSSor was designed to help security testers by performing semi-automatic reflected and persistent XSS detection tests.
GitHub
GitHub - whitel1st/docem: Uility to embed XXE and XSS payloads in docx,odt,pptx,etc (OXML_XEE on steroids)
GitHub
GitHub - shadow-workers/shadow-workers: Shadow Workers is a free and open source C2 and proxy designed for penetration testers to help in the exploitation of XSS and malicious Service Workers (SW)
GitHub
Top 500 Most Important XSS Cheat Sheet for Web Application Pentesting
GBHackers On Security
GitHub - thenurhabib/collector: Collect XSS vulnerable parameters from entire domain.
GitHub
PayloadsAllTheThings/XSS Injection at master ยท swisskyrepo/PayloadsAllTheThings
GitHub
GitHub - payloadbox/xss-payload-list: ๐ฏ Cross Site Scripting ( XSS ) Vulnerability Payload List
GitHub
GitHub - nettitude/xss_payloads: Exploitation for XSS
GitHub
xss payloads collect
XSS Payloads
GitHub - cujanovic/Markdown-XSS-Payloads: XSS payloads for exploiting Markdown syntax
GitHub
Cross-site Scripting Payloads Cheat Sheet
LinuxSec Exploit
Polyglots: The Ultimate XSS Payloads
Chef Secure
Common XSS payloads I use
๐ป | Blog
GitHub - ihebski/XSS-Payloads: Collection of XSS Payloads for fun and profit
GitHub