https://danielmiessler.com/blog/the-sleepy-puppy-xss-payload-management-framework
I am one of the leaders of the OWASP Bay Area group, and we’ve had some great local meetups recently—one at Twitter and another at Netflix. At the N
sleepypuppyxsspayloadmanagement
https://academy.hackthebox.com/course/preview/cross-site-scripting-xss
Cross-Site Scripting (XSS) vulnerabilities are among the most common web application vulnerabilities. An XSS vulnerability may allow an attacker to execute a...
crosssitescriptingxsscourse
https://portswigger.net/research/xss-without-html-client-side-template-injection-with-angularjs
Abstract Naive use of the extremely popular JavaScript framework AngularJS is exposing numerous websites to Angular Template Injection. This relatively low...
xsswithouthtmlclientside
https://portswigger.net/blog/introducing-dom-invader
Of the three main types of XSS, DOM-based XSS is by far the most difficult to find and exploit. But we come bearing good news! PortSwigger just released a new...
introducingdominvaderxssgot
https://syntax.fm/show/290/potluck-is-angular-good-stencil-js-self-xss-svgs-in-react-social-platforms-for-devs-project-handoff-cleaning-knives-more
In this potluck episode, Scott and Wes answer developer questions on topics like Target blank links security, Stencil JS, senior developers, Angular careers,...
potluckangulargoodstenciljs
https://portswigger.net/research/portable-data-exfiltration
Abstract PDF documents and PDF generators are ubiquitous on the web, and so are injection vulnerabilities. Did you know that controlling a measly HTTP...
data exfiltrationportablexsspdfsresearch
https://academy.hackthebox.com/course/preview/advanced-xss-and-csrf-exploitation
Modern web browsers and applications utilize a variety of security measures to protect against CSRF and XSS vulnerabilities, rendering their exploitation mor...
advancedxsscsrfexploitationcourse
https://adversa.ai/blog/lenovo-ai-chatbot-incident-critical-xss-vulnerability-exposes-enterprise-ai-security-gaps/
Aug 22, 2025 - The Lenovo AI Chatbot Incident shows how a 400-char prompt triggered a critical XSS flaw, proving AI systems can turn simple exploits into major security risks.
ai chatbotlenovoincidentcriticalxss
https://www.ruby-lang.org/en/news/2013/02/06/rdoc-xss-cve-2013-0256/
RDoc documentation generated by rdoc bundled with ruby are vulnerable toan XSS exploit. All ruby users are recommended to update ruby to newerversion which i...
xssexploitdocumentationgeneratedcve
https://oshogbo.com/blog/75/
Some time ago, Michał Bentkowski published an XSS challenge on his twitter. I accepted the challenge, and here is my story.
mbxsschallengeoshogbovx
https://dev.to/sylwia-lask/a-five-minute-ui-feature-that-became-an-xss-time-bomb-f5i
Dec 17, 2025 - Can a simple script — a trivial visual effect — put your application at risk? Oh yes. And you might... Tagged with webdev, javascript, security, frontend.
fiveminuteuifeaturebecame
https://cyberint.com/blog/dark-web/the-downfall-of-xss-forum/
Oct 5, 2025
downfallxssforum
https://blog.nette.org/en/quiz-can-you-defend-against-xss-vulnerability
Put your security knowledge to the test with this quiz! Can you prevent an attacker from taking control of an HTML page?
quizdefendxssvulnerabilitynette
https://traefik.io/blog/exploring-traefiks-waf-integration-and-how-to-make-it-23x-faster
Learn how to stop SQL injection, cross-site scripting, and other known attacks with Traefik's Web Application Firewall (WAF).
stopxssattackseasilytraefik
https://training.linuxfoundation.org/express-learning/xss-exploits-and-defenses-lfel1010/
Jan 2, 2025 - Easily grow your cybersecurity maturity by learning to counter the top security vulnerability, cross-site scripting (XSS)!
training courselinux foundationxssexploitsdefenses
https://securinglaravel.com/security-tip-when-is-xss-not-strictly-xss-but-still-bad/
Sep 8, 2025 - [Tip #121] Technically, XSS involves injecting malicious Javascript, but sometimes you don't need any JS to get up to mischief! 😈
securitytipxssstrictlystill
https://syntax.fm/show/731/client-side-security-xss-attacks-and-csp-with-stripe-s-alex-sexton
Alex Sexton from Stripe discusses CSP (Content Security Policy) and client side security best practices, drawing on 11 years of experience at Stripe.
clientsidesecurityxssattacks
https://shazzer.co.uk/vectors/68f8822088350896a081d946
Electron Browser XSS TEST
electronxsstest
https://jsoup.org/
Open source Java HTML parser, with the best of HTML5 DOM methods and CSS selectors, for easy data extraction.
javahtmlparserbuiltediting
https://portswigger.net/research/xss-in-hidden-input-fields
At PortSwigger, we regularly run pre-release builds of Burp Suite against an internal testbed of popular web applications to make sure it's behaving...
xsshiddeninputfieldsresearch
https://tarnkappe.info/artikel/szene/dark-commerce/xss-is-beschlagnahmt-mitbetreiber-des-fraud-forums-in-kiew-verhaftet-318531.html
Jul 24, 2025 - Die Domain xss.is ist beschlagnahmt. Einen Admin des Fraud-Forums verhaftete man am Dienstag. Der Mann soll 7 Millionen Euro verdient haben.
xssbeschlagnahmtdesfraudforums
https://dev.to/mahin101/advent-of-cyber-2025-day-10-writeup-cross-site-scripting-xss-tryhackme-30i6
Jan 3, 2026 - Usually, a website or web app displays information from the server. However, as users, we can also... Tagged with tryhackme, xss, security.
adventcyberdaywriteupcross