https://owasp.org/www-community/attacks/xss/
Cross Site Scripting (XSS) | OWASP Foundation
Cross Site Scripting (XSS) on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.
cross site scriptingxssowaspfoundation
https://portswigger.net/web-security/cross-site-scripting/cheat-sheet
Cross-Site Scripting (XSS) Cheat Sheet - 2026 Edition | Web Security Academy
Interactive cross-site scripting (XSS) cheat sheet for 2026, brought to you by PortSwigger. Actively maintained, and regularly updated with new vectors.
cross site scriptingcheat sheetweb securityxss
https://thespanner.co.uk/2012/05/01/xss-technique-without-parentheses
XSS technique without parentheses - The Spanner
This is a very old technique I discovered years ago which I used to bypass a filter and it's pretty awesome. It might come in handy to bypass a WAF or filter...
xsstechniquewithoutparenthesesspanner
https://web.dev/articles/strict-csp
Mitigate cross-site scripting (XSS) with a strict Content Security Policy (CSP) | Articles | web.dev
Sep 13, 2024 - Learn how to deploy a CSP based on script nonces or hashes as a defense-in-depth against cross-site scripting.
https://jsoup.org/
jsoup: Java HTML parser, built for HTML editing, cleaning, scraping, and XSS safety
Open source Java HTML parser, with the best of HTML5 DOM methods and CSS selectors, for easy data extraction.
html parserbuilt for
https://github.com/mybb/mybb/security/advisories/GHSA-p766-qqxv-rfc2
Buddy/ignore list username XSS · Advisory · mybb/mybb · GitHub
GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.
ignore listbuddyusernamexssadvisory
https://github.com/mybb/mybb/security/advisories/GHSA-wj33-q7vj-9fr8
Visual editor persistent XSS · Advisory · mybb/mybb · GitHub
GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.
visual editorpersistentxssadvisorymybb
https://advisories.gitlab.com/maven/org.keycloak/keycloak-core/CVE-2024-4028/
Keycloak allows cross-site scripting (XSS) | GitLab Advisory Database (GLAD)
CVE-2024-4028 Keycloak allows cross-site scripting (XSS): A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious...
cross site scriptingkeycloakallowsxssgitlab
https://thehackernews.com/2012/01/cross-site-scripting-xss-vulnerability.html
Cross Site Scripting (XSS) Vulnerability in Google
Cross Site Scripting (XSS) Vulnerability in Google | Read more hacking news on The Hacker News cybersecurity news website and learn how to protect against...
cross site scriptingxssvulnerabilitygoogle
https://advisories.gitlab.com/npm/trix/CVE-2024-53847/
Trix editor subject to XSS vulnerabilities on copy & paste | GitLab Advisory Database (GLAD)
https://ndevtk.github.io/writeups/2026/03/19/google-xss-3/?ref=rosecurify.com
Google XSS part 3 | Writeups
Mar 19, 2026 - XSS in Firebase Studio (Awarded $7500, Deprecated)
googlexsspartwriteups
https://advisories.gitlab.com/golang/github.com/siyuan-note/siyuan/kernel/CVE-2026-34605/
SiYuan vulnerable to reflected XSS via SVG namespace prefix bypass in SanitizeSVG (getDynamicIcon,...
CVE-2026-34605 SiYuan vulnerable to reflected XSS via SVG namespace prefix bypass in SanitizeSVG (getDynamicIcon, unauthenticated): The SanitizeSVG function...
https://security.googleblog.com/2009/03/reducing-xss-by-way-of-automatic.html?showComment=1241938380000&hl=fr_CA
Google Online Security Blog: Reducing XSS by way of Automatic Context-Aware Escaping in Template...
Posted by Jad S. Boutros, Security Team Building on our earlier posts on defenses against web application flaws [ "Automating Web Applicatio...
https://advisories.gitlab.com/npm/n8n/CVE-2025-61914/
n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox | GitLab...
CVE-2025-61914 n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox: A stored Cross-Site Scripting (XSS) vulnerability may...
https://advisories.gitlab.com/golang/github.com/quantumnous/new-api/CVE-2026-25802/
New API has Potential XSS in its MarkdownRenderer component | GitLab Advisory Database (GLAD)
CVE-2026-25802 New API has Potential XSS in its MarkdownRenderer component: A potential unsafe operation occurs in component MarkdownRenderer.jsx, allowing for...
https://advisories.gitlab.com/npm/n8n/CVE-2025-58177/
Stored XSS in n8n LangChain Chat Trigger Node via initialMessages Parameter | GitLab Advisory...
CVE-2025-58177 Stored XSS in n8n LangChain Chat Trigger Node via initialMessages Parameter: A stored Cross-Site Scripting (XSS) vulnerability was identified in...
https://advisories.gitlab.com/pypi/mayan-edms/CVE-2022-47419/
Mayan EDMS DMS XSS vulnerability | GitLab Advisory Database (GLAD)
CVE-2022-47419 Mayan EDMS DMS XSS vulnerability: An XSS vulnerability was discovered in the Mayan EDMS DMS. Successful XSS exploitation was observed in the...
mayan edmsxssvulnerabilitygitlabadvisory
https://advisories.gitlab.com/composer/pimcore/pimcore/CVE-2023-2332/
Cross-site Scripting (XSS) in Conditions tab of Pricing Rules | GitLab Advisory Database (GLAD)
CVE-2023-2332 Cross-site Scripting (XSS) in Conditions tab of Pricing Rules: This vulnerability has the potential to steal a user's cookie and gain...
cross site scripting
https://advisories.gitlab.com/npm/@nuxtjs/mdc/CVE-2025-54075/
Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering | GitLab...
CVE-2025-54075 Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering: A remote script-inclusion / stored XSS vulnerability in...
https://advisories.gitlab.com/maven/com.liferay/com.liferay.document.library.web/CVE-2022-42113/
Liferay Portal and Liferay DXP Vulnerable to XSS via the Document Library Module | GitLab Advisory...
CVE-2022-42113 Liferay Portal and Liferay DXP Vulnerable to XSS via the Document Library Module: A Cross-site scripting (XSS) vulnerability in Document Library...
https://advisories.gitlab.com/composer/thorsten/phpmyfaq/CVE-2025-68951/
phpMyFAQ has Stored XSS in user list via admin-managed display_name | GitLab Advisory Database...
CVE-2025-68951 phpMyFAQ has Stored XSS in user list via admin-managed display_name: A stored cross-site scripting (XSS) vulnerability allows an attacker to...
https://advisories.gitlab.com/pypi/octoprint/CVE-2024-28237/
XSS via the "Snapshot Test" feature in Classic Webcam plugin settings | GitLab Advisory Database...
CVE-2024-28237 XSS via the "Snapshot Test" feature in Classic Webcam plugin settings: OctoPrint versions up until and including 1.9.3 contain a vulnerability...
https://taosecurity.blogspot.com/2007/07/review-of-xss-attacks-posted.html?showComment=1252258935265
Review of XSS Attacks Posted
Richard Bejtlich's blog on digital security, strategic thought, and military history.
xss attacksreviewposted
https://www.ibm.com/support/pages/apar/PI93897
PI93897: PERSISTENT CROSS SITE SCRIPTING (XSS) ISSUE IN COGNOS 10.2.2
XSS error (see screenshot in testcase)
cross site scriptingpersistent
https://advisories.gitlab.com/golang/github.com/openziti/zrok/v2/CVE-2026-40302/
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering |...
CVE-2026-40302 zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering: Summary The proxyUi template engine uses Go's...
github oauth
https://vuxml.freebsd.org/freebsd/c2c89dea-2859-4231-8f3b-012be0d475ff.html
VuXML: py-django-photologue -- XSS vulnerability
vuxmlpydjangoxssvulnerability
https://advisories.gitlab.com/composer/starcitizentools/citizen-skin/CVE-2025-62508/
Citizen vulnerable to stored XSS in sticky header button messages | GitLab Advisory Database (GLAD)
CVE-2025-62508 Citizen vulnerable to stored XSS in sticky header button messages: The JS implementation for copying button labels to the sticky header in the...
https://advisories.gitlab.com/composer/shopware/shopware/GHSA-9v82-vcjx-m76j/
Shopware: Reflective Cross Site-Scripting (XSS) in CMS components | GitLab Advisory Database (GLAD)
GHSA-9v82-vcjx-m76j Shopware: Reflective Cross Site-Scripting (XSS) in CMS components: When an application uses input fields, it is important that user input...
cross site scripting
https://advisories.gitlab.com/maven/org.xwiki.platform/xwiki-platform-flamingo-theme-ui/CVE-2022-29251/
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | GitLab Advisory...
CVE-2022-29251 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS): XWiki Platform Flamingo Theme UI is a tool that allows...
https://advisories.gitlab.com/pypi/mezzanine/CVE-2020-19002/
Mezzanine Cross Site Scripting (XSS) vulnerability | GitLab Advisory Database (GLAD)
CVE-2020-19002 Mezzanine Cross Site Scripting (XSS) vulnerability: Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary...
cross site scriptingmezzaninexssvulnerabilitygitlab
https://userapps.support.sap.com/sap/support/knowledge/en/2584438
2584438 - Vulnerability scan against Fiori Launchpad reports XSS in PAGE_BUILDER service | SAP...
https://advisories.gitlab.com/composer/opensource-workshop/connect-cms/CVE-2026-32278/
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin | GitLab...
CVE-2026-32278 Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin: A Stored Cross-site Scripting (XSS) issue exists in the...
https://advisories.gitlab.com/npm/@pdfme/schemas/GHSA-xgx4-2wgv-4jhm/
PDFME has XSS via Unsanitized i18n Label Injection into innerHTML in multiVariableText propPanel |...
GHSA-xgx4-2wgv-4jhm PDFME has XSS via Unsanitized i18n Label Injection into innerHTML in multiVariableText propPanel: The multiVariableText property panel in...
https://pastebin.com/B8JBzaE2
[MINI EXPLOIT] Wordpress Theme Photocrati 4.x.x - SQLI & XSS - Pastebin.com
Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time.
wordpress thememiniexploitphotocrati
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2025-43823/
Liferay Portal is vulnerable to XSS through its Commerce Search Result widget | GitLab Advisory...
CVE-2025-43823 Liferay Portal is vulnerable to XSS through its Commerce Search Result widget: Cross-site Scripting (XSS) vulnerability in the Commerce Search...
https://advisories.gitlab.com/composer/craftcms/commerce/CVE-2026-25483/
Craft Commerce has Stored XSS via Order Status Message with potential database exfiltration |...
CVE-2026-25483 Craft Commerce has Stored XSS via Order Status Message with potential database exfiltration: A stored XSS vulnerability exists in Craft...
https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/message/MCYGUEP5HPMTY53K76E3DZQ5UFL4MRHH/
Re: [aur-general] Moving xss-lock to community - Aur-general - lists.archlinux.org
general movingto communityaurxss
https://advisories.gitlab.com/maven/org.geoserver.web/gs-web-app/CVE-2025-21621/
GeoServer has a Reflected Cross-Site Scripting (XSS) vulnerability in its WMS GetFeatureInfo HTML...
CVE-2025-21621 GeoServer has a Reflected Cross-Site Scripting (XSS) vulnerability in its WMS GetFeatureInfo HTML format: A reflected cross-site scripting (XSS)...
https://advisories.gitlab.com/npm/open-webui/CVE-2025-64495/
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled...
CVE-2025-64495 Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE: The functionality that...
https://advisories.gitlab.com/nuget/dotnetnuke.core/CVE-2026-24837/
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal | GitLab Advisory...
CVE-2026-24837 DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal: A module friendly name could include scripts that will run...
https://groups.google.com/g/ruby-security-ann/c/5ZI1-H5OoIM/m/ZNq4FoR2GnIJ
[CVE-2013-6416] XSS Vulnerability in simple_format helper
cvexssvulnerabilitysimpleformat
https://advisories.gitlab.com/composer/bagisto/bagisto/CVE-2025-60880/
Bagisto is vulnerable to XSS through Admin Panel's product creation path | GitLab Advisory Database...
CVE-2025-60880 Bagisto is vulnerable to XSS through Admin Panel's product creation path: An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6...
https://patchstack.com/database/wordpress/plugin/cartflows/vulnerability/wordpress-cartflows-plugin-2-0-1-cross-site-scripting-xss-vulnerability
Cross Site Scripting (XSS) in WordPress CartFlows Plugin - Patchstack
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
cross site scriptingxsswordpresscartflowsplugin
https://docs.rs/crate/cargo-xss-testing/latest
cargo-xss-testing 0.4.6 - Docs.rs
cargoxsstestingdocsrs
https://advisories.gitlab.com/composer/silverstripe/framework/GHSA-r32j-mr8p-hfp8/
Silverstripe XSS in TreeDropdownField and TreeMultiSelectField | GitLab Advisory Database (GLAD)
GHSA-r32j-mr8p-hfp8 Silverstripe XSS in TreeDropdownField and TreeMultiSelectField: A cross-site scripting vulnerability has been discovered in the...
silverstripexssgitlabadvisorydatabase
https://advisories.gitlab.com/composer/craftcms/commerce/CVE-2026-29175/
Craft Commerce has multiple Stored XSS in Commerce Inventory Page, Leading to Session Hijacking |...
CVE-2026-29175 Craft Commerce has multiple Stored XSS in Commerce Inventory Page, Leading to Session Hijacking: Stored XSS vulnerabilities exist in the...
https://advisories.gitlab.com/golang/github.com/zitadel/zitadel/CVE-2024-29891/
ZITADEL's Improper Content-Type Validation Leads to Account Takeover via Stored XSS + CSP Bypass |...
CVE-2024-29891 ZITADEL's Improper Content-Type Validation Leads to Account Takeover via Stored XSS + CSP Bypass: ZITADEL users can upload their own avatar...
https://advisories.gitlab.com/npm/n8n/GHSA-3c7f-5hgj-h279/
n8n has XSS in Chat Trigger Node through Custom CSS | GitLab Advisory Database (GLAD)
GHSA-3c7f-5hgj-h279 n8n has XSS in Chat Trigger Node through Custom CSS: An authenticated user with permission to create or modify workflows could inject...
https://security.googleblog.com/2009/03/reducing-xss-by-way-of-automatic.html?showComment=1238989020000&hl=fr_CA
Google Online Security Blog: Reducing XSS by way of Automatic Context-Aware Escaping in Template...
Posted by Jad S. Boutros, Security Team Building on our earlier posts on defenses against web application flaws [ "Automating Web Applicatio...
https://advisories.gitlab.com/maven/org.webjars.npm/jquery-ui/CVE-2022-31160/
jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label |...
CVE-2022-31160 jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label: Initializing a checkboxradio widget on an...
https://advisories.gitlab.com/cargo/vaultwarden/CVE-2024-55226/
Vaultwarden authenticated reflected cross-site scripting (XSS) vulnerability | GitLab Advisory...
CVE-2024-55226 Vaultwarden authenticated reflected cross-site scripting (XSS) vulnerability: Vaultwarden v1.32.5 was discovered to contain an authenticated...
cross site scriptingvaultwardenauthenticatedreflectedxss
https://advisories.gitlab.com/composer/openmage/magento-lts/GHSA-gp6m-fq6h-cjcx/
Magento LTS vulnerable to stored XSS in admin file form | GitLab Advisory Database (GLAD)
GHSA-gp6m-fq6h-cjcx Magento LTS vulnerable to stored XSS in admin file form: Summary OpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability...
https://knowledge.broadcom.com/external/article/276324/identity-manager-or-identity-portal-vuln.html
Identity Manager or Identity Portal Vulnerability regarding XSS and Clickjacking
identity managerportalvulnerabilityregardingxss
https://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html
Quick.Forum 'topic field' XSS and 'page' & 'iCategory' SQL injection
forum topicquickfieldxsssql
https://patchstack.com/database/wordpress/plugin/astra-widgets/vulnerability/wordpress-astra-widgets-plugin-1-2-14-stored-cross-site-scripting-xss-vulnerability
Cross Site Scripting (XSS) in WordPress Astra Widgets Plugin - Patchstack
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
cross site scriptingxsswordpressastrawidgets
https://bughunters.google.com/reports/vrp/qZmd7EJHp/report
Reflected Cross-Site Scripting (XSS) on Google Acquisition Domain | Google Bug Hunters
Found a security vulnerability? Discover our forms for reporting security issues to Google: for the standard VRP, Google Play, and Play Data Abuse.
cross site scriptingon googlereflectedxss
https://advisories.gitlab.com/golang/github.com/casdoor/casdoor/CVE-2026-5468/
Casdoor vulnerable to Stored XSS via Application formCss / formSideHtml | GitLab Advisory Database...
CVE-2026-5468 Casdoor vulnerable to Stored XSS via Application formCss / formSideHtml: A security flaw has been discovered in Casdoor 2.356.0. This affects the...
https://www.drupal.org/node/2459315
Crumbs - Moderately Critical - Cross Site Scripting (XSS) - SA-CONTRIB-2015-082 | Drupal.org
Jun 11, 2015 - Advisory ID: DRUPAL-SA-CONTRIB-2015-082 Project: Crumbs (third-party module) Version: 7.x Date: 2015-March-25 Security risk: 13/25 ( Moderately Critical)...
cross site scripting
https://speakerdeck.com/lmt_swallow/gimme-a-bit-exploring-attacks-in-the-post-xss-world
"Gimme a bit!" - Exploring Attacks in the "Post-XSS" World - Speaker Deck
Presented at: https://shibuyaxss.connpass.com/event/128168/
in the posta bit
https://advisories.gitlab.com/npm/astro/CVE-2025-59837/
Astro's bypass of image proxy domain validation leads to SSRF and potential XSS | GitLab Advisory...
CVE-2025-59837 Astro's bypass of image proxy domain validation leads to SSRF and potential XSS: This is a patch bypass of CVE-2025-58179 in commit 9ecf359. The...
https://advisories.gitlab.com/npm/koa/CVE-2025-32379/
Koajs vulnerable to Cross-Site Scripting (XSS) at ctx.redirect() function | GitLab Advisory...
cross site scripting
https://4t64ubva.xssy.uk/
Unicode XSS
unicodexss
https://security.googleblog.com/2009/03/reducing-xss-by-way-of-automatic.html?showComment=1239706440000&hl=es
Google Online Security Blog: Reducing XSS by way of Automatic Context-Aware Escaping in Template...
Posted by Jad S. Boutros, Security Team Building on our earlier posts on defenses against web application flaws [ "Automating Web Applicatio...
https://security.googleblog.com/2009/03/reducing-xss-by-way-of-automatic.html?showComment=1238586540000&hl=fr_CA
Google Online Security Blog: Reducing XSS by way of Automatic Context-Aware Escaping in Template...
Posted by Jad S. Boutros, Security Team Building on our earlier posts on defenses against web application flaws [ "Automating Web Applicatio...
https://advisories.gitlab.com/golang/code.vikunja.io/api/CVE-2026-25935/
Vikunja Vulnerable to XSS Via Task Preview | GitLab Advisory Database (GLAD)
CVE-2026-25935 Vikunja Vulnerable to XSS Via Task Preview: The task preview component creates a unparented div. The div's innerHtml is set to the unescaped...
vikunjavulnerablexssvia
https://developer.joomla.org/security-centre/570-20131101-core-xss-vulnerability.html
[20131101] Core XSS Vulnerability
corexssvulnerability
https://advisories.gitlab.com/composer/magento/community-edition/CVE-2025-24412/
Magento Stored Cross-Site Scripting (XSS) Vulnerability | GitLab Advisory Database (GLAD)
CVE-2025-24412 Magento Stored Cross-Site Scripting (XSS) Vulnerability: Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and...
cross site scriptingmagentostored
https://groups.google.com/g/rubyonrails-security/c/SKs_SiwWGQ8
XSS Vulnerability in Ruby on Rails
xssvulnerabilityrubyrails
https://advisories.gitlab.com/pypi/omero-web/GHSA-j4gv-6x9v-v23g/
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack | GitLab Advisory...
GHSA-j4gv-6x9v-v23g OMERO.web uses jquery-form library, which may be vulnerable to XSS attack: OMERO.web uses the jquery-form library throughout to handle form...
https://patchstack.com/database/wordpress/plugin/ultimate_vc_addons/vulnerability/wordpress-ultimate-addons-for-wpbakery-page-builder-plugin-3-19-20-authenticated-contributor-stored-cross-site-scripting-via-shortcode-vulnerability-4
Cross Site Scripting (XSS) in WordPress Ultimate Addons for WPBakery Page Builder Plugin -...
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
cross site scripting
https://advisories.gitlab.com/composer/phpmyfaq/phpmyfaq/CVE-2026-34729/
phpMyFAQ: Stored XSS via Regex Bypass in Filter::removeAttributes() | GitLab Advisory Database...
CVE-2026-34729 phpMyFAQ: Stored XSS via Regex Bypass in Filter::removeAttributes(): The sanitization pipeline for FAQ content is: Filter::filterVar($input,...
https://developer.joomla.org/security-centre/937-20240703-core-xss-in-stringhelper-truncate-method.html
[20240703] - Core - XSS in StringHelper::truncate method
corexsstruncatemethod
https://docs.google.com/presentation/d/1gj98wzYiZ9K_JEXYon94jnF4jzacGgO0vDlLJR1PtA4/edit
[CS161 FA22] Lecture 14: XSS and UI Attacks - Google Slides
XSS and UI Attacks CS 161 Fall 2022 - Lecture 14
lecturexssuiattacksgoogle
https://advisories.gitlab.com/npm/ckeditor5-premium-features/CVE-2025-25299/
Cross-site scripting (XSS) in the CKEditor 5 real-time collaboration package | GitLab Advisory...
CVE-2025-25299 Cross-site scripting (XSS) in the CKEditor 5 real-time collaboration package: During a recent internal audit, we identified a Cross-Site...
cross site scripting
https://en-ca.wordpress.org/plugins/tags/xss-protection/
Plugins categorized as xss protection | WordPress.org English (Canada)
pluginscategorizedxssprotectionwordpress
https://advisories.gitlab.com/maven/org.jenkins-ci.plugins/bart/CVE-2022-45387/
Jenkins BART Plugin vulnerable to cross-site scripting (XSS) | GitLab Advisory Database (GLAD)
CVE-2022-45387 Jenkins BART Plugin vulnerable to cross-site scripting (XSS): Jenkins BART Plugin 1.0.3 and earlier does not escape the parsed content of build...
cross site scripting
https://advisories.gitlab.com/nuget/dotnetnuke.core/CVE-2025-59546/
DNN Vulnerable to Stored XSS Using Backend Admin Credentials | GitLab Advisory Database (GLAD)
CVE-2025-59546 DNN Vulnerable to Stored XSS Using Backend Admin Credentials: Users that can edit modules could set a title that includes scripts.
https://nomoreroot.blogspot.com/2008/08/ie8-xss-filter.html
No More Root: IE8 XSS filter
Since IE8 beta2 is out I downloaded and installed it, I wanted to take a look at the brand new XSS filter ( See here *1). Basically I wanted...
no morerootxssfilter
https://advisories.gitlab.com/golang/github.com/siyuan-note/siyuan/kernel/CVE-2026-39846/
SiYuan: Remote Code Execution in the Electron desktop client via stored XSS in synced table...
CVE-2026-39846 SiYuan: Remote Code Execution in the Electron desktop client via stored XSS in synced table captions: A malicious note synced to another user...
https://patchstack.com/database/wordpress/plugin/ultimate-addons-for-gutenberg/vulnerability/wordpress-spectra-plugin-2-19-14-authenticated-contributor-stored-cross-site-scripting-via-custom-css-vulnerability
Cross Site Scripting (XSS) in WordPress Spectra Plugin - Patchstack
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
cross site scriptingxsswordpressspectraplugin
https://advisories.gitlab.com/golang/github.com/siyuan-note/siyuan/kernel/CVE-2026-34448/
SiYuan: Stored XSS in Attribute View Gallery/Kanban Cover Rendering Allows Arbitrary Command...
CVE-2026-34448 SiYuan: Stored XSS in Attribute View Gallery/Kanban Cover Rendering Allows Arbitrary Command Execution in Desktop Client: An attacker who can...
https://bughunters.google.com/reports/vrp/M1xsjw9js/comments
XSS in https://run.qwiklabs.com/my_account | Google Bug Hunters
Found a security vulnerability? Discover our forms for reporting security issues to Google: for the standard VRP, Google Play, and Play Data Abuse.
my accountxsshttpsrunqwiklabs
https://advisories.gitlab.com/composer/krayin/laravel-crm/CVE-2026-5370/
Krayin CRM is vulnerable to Cross-site Scripting (XSS) | GitLab Advisory Database (GLAD)
CVE-2026-5370 Krayin CRM is vulnerable to Cross-site Scripting (XSS): A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function...
cross site scripting
https://advisories.gitlab.com/composer/getkirby/cms/CVE-2025-65012/
Kirby CMS has cross-site scripting (XSS) in the changes dialog | GitLab Advisory Database (GLAD)
CVE-2025-65012 Kirby CMS has cross-site scripting (XSS) in the changes dialog: The "Changes" dialog in the Panel displays all content models (pages, files,...
https://funky-slipper-44f.notion.site/Privilege-Escalation-using-XSS-d98e8f4a738146e5bf6aefe4c51c33f7
Privilege Escalation using XSS | Notion
CSRF Bypass in Rails Application:
privilege escalationusingxssnotion
https://www.meetup.com/owasp-wellington/events/239202702/
Developer's guide to preventing XSS, Mon, May 29, 2017, 6:00 PM | Meetup
Fresh from OWASP NZ Day 2017 (https://www.owasp.org/index.php/OWASP_New_Zealand_Day_2017), we bring you this talk: Abstract An introductory talk on cross site...
https://advisories.gitlab.com/composer/silverstripe/framework/CVE-2024-47605/
Silverstripe Framework has a XSS via insert media remote file oembed | GitLab Advisory Database...
CVE-2024-47605 Silverstripe Framework has a XSS via insert media remote file oembed: When using the "insert media" functionality, the linked oEmbed JSON...
https://advisories.gitlab.com/composer/phpoffice/phpexcel/CVE-2025-22131/
Cross-Site Scripting (XSS) vulnerability in generateNavigation() function in PhpSpreadsheet |...
CVE-2025-22131 Cross-Site Scripting (XSS) vulnerability in generateNavigation() function in PhpSpreadsheet: The researcher discovered zero-day vulnerability...
cross site scriptingxssvulnerabilityfunction
https://advisories.gitlab.com/composer/magento/project-community-edition/CVE-2025-24410/
Magento Stored Cross-Site Scripting (XSS) Vulnerability | GitLab Advisory Database (GLAD)
CVE-2025-24410 Magento Stored Cross-Site Scripting (XSS) Vulnerability: Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and...
cross site scriptingmagentostored
https://advisories.gitlab.com/golang/github.com/prometheus/prometheus/GHSA-fw8g-cg8f-9j28/
Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI...
GHSA-fw8g-cg8f-9j28 Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display: In the Prometheus server's...
https://advisories.gitlab.com/golang/github.com/apache/incubator-answer/CVE-2024-29217/
Apache Answer: XSS vulnerability when changing personal website | GitLab Advisory Database (GLAD)
CVE-2024-29217 Apache Answer: XSS vulnerability when changing personal website: Improper Neutralization of Input During Web Page Generation ('Cross-site...
apache answer
https://advisories.gitlab.com/npm/@excalidraw/excalidraw/GHSA-39h7-pwv7-rc3x/
Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering) | GitLab...
GHSA-39h7-pwv7-rc3x Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering): @excalidraw/excalidraw@0.18.0 depends on a Mermaid...
https://advisories.gitlab.com/golang/github.com/zitadel/zitadel/CVE-2026-29191/
ZITADEL has 1-Click Account Takeover via XSS in /saml-post Endpoint | GitLab Advisory Database...
CVE-2026-29191 ZITADEL has 1-Click Account Takeover via XSS in /saml-post Endpoint: A vulnerability was discovered in Zitadel's login V2 interface that allowed...
https://advisories.gitlab.com/golang/github.com/mattermost/mattermost-server/CVE-2017-18879/
Mattermost Server is vulnerable to XSS through author_link field in Slack attachments | GitLab...
CVE-2017-18879 Mattermost Server is vulnerable to XSS through author_link field in Slack attachments: An issue was discovered in Mattermost Server before...
https://advisories.gitlab.com/pypi/label-studio/CVE-2026-22033/
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile...
CVE-2026-22033 Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field: A persistent stored...
https://advisories.gitlab.com/npm/serve-lite/CVE-2022-25847/
Cross-site Scripting (XSS) in serve-lite | GitLab Advisory Database (GLAD)
CVE-2022-25847 Cross-site Scripting (XSS) in serve-lite: All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it...
cross site scriptingxss
https://advisories.gitlab.com/composer/craftcms/cms/CVE-2026-31859/
CraftCMS vulnerable to reflective XSS via incomplete return URL sanitization | GitLab Advisory...
CVE-2026-31859 CraftCMS vulnerable to reflective XSS via incomplete return URL sanitization: The fix for CVE-2025-35939 in craftcms/cms introduced a...
https://advisories.gitlab.com/composer/getgrav/grav/CVE-2026-42841/
Grav CMS vulnerable to stored XSS via Markdown media attribute() action | GitLab Advisory Database...
CVE-2026-42841 Grav CMS vulnerable to stored XSS via Markdown media attribute() action: An authenticated user with page editing permissions can inject an...
https://github.com/secdec/xssmap
GitHub - secdec/xssmap: Intelligent XSS detection tool that uses human techniques for looking for...
Intelligent XSS detection tool that uses human techniques for looking for reflected cross-site scripting (XSS) vulnerabilities - secdec/xssmap
https://knowledge.broadcom.com/external/article/165915/content-security-policy-csp-example-for.html
Content Security Policy (CSP) example for XSS prevention
content security policycspexamplexssprevention