https://shibuyaxss.connpass.com/event/287631/
Shibuya.XSS techtalk #12 - connpass
Shibuya.XSS テクニカルトーク#12 を2023年7月25日(火)に開催します!4年ぶりの開催です! ## スピーカー * @kinugawamasato さん 「Pwn2OwnでMicrosoft Teamsをハッキングして2000万円を獲得した方法」 * @shhnjk さん 「Same-Origin...
shibuyaxsstechtalkconnpass
https://liveoverflow.com/do-not-use-alert-1-in-xss/
Do NOT use alert(1) in XSS
Jul 31, 2021 - Using the alert(1) XSS payload doesn't actually tell you where the payload is executed. Choosing alert(document.domain) and alert(window.origin) instead tells...
usealertxss
https://www.codecademy.com/learn/defending-express-applications-from-sql-injection-xss-csrf-attacks
Defending Node Applications from SQL Injection, XSS, & CSRF Attacks | Codecademy
sql injectiondefendingnodeapplicationsxss
https://www.aikido.dev/blog/xss-vulnerabilities-in-mailcow
Multiple XSS Vulnerabilities Found in Mailcow, Including Unauthenticated Account Takeover
Apr 17, 2026 - Aikido's AI pentest agent found three XSS vulnerabilities in Mailcow, one of which let unauthenticated attackers take over administrator accounts. All issues...
account takeovermultiplexssvulnerabilitiesfound
https://www.aikido.dev/blog/storybooks-websockets-attack
Persistent XSS/RCE using WebSockets in Storybook (CVE-2026-27148)
Mar 6, 2026 - CVE-2026-27148 exposes a WebSocket hijacking flaw in Storybook that can escalate into supply chain compromise. Learn the attack path, impact, and how to...
using websocketspersistentxssrcestorybook
https://crosssitescripting.seowebchecker.com/
XSS Cross Site Scripting and Website Vulnerability Checker
cross site scriptingxsswebsitevulnerabilitychecker
https://7asecurity.com/free-workshop-mobile-deeplinks-xss/b
Hacking Android & iOS apps with Deep Links and XSS | Blog
No money? no problem. Get a Free Pentest or a Free Course! | Blog
ios appsdeep linkshackingandroidxss
https://training.linuxfoundation.org/express-learning/xss-exploits-and-defenses-lfel1010/
XSS Exploits and Defenses Training Course | Linux Foundation
Jan 28, 2026 - Easily grow your cybersecurity maturity by learning to counter the top security vulnerability, cross-site scripting (XSS)!
training courselinux foundationxssexploitsdefenses
https://extensions.joomla.org/vulnerable-extensions/vulnerable/easyshop-1-4-1-xss-cross-site-scripting/
EasyShop, 1.4.1, XSS (Cross Site Scripting)
EasyShop, 1.4.1, 3rd party extension
cross site scripting1 4easyshopxss
https://securinglaravel.com/security-tip-when-is-xss-not-strictly-xss-but-still-bad/
Security Tip: When Is XSS Not Strictly XSS? (But Still Bad!)
Sep 8, 2025 - [Tip #121] Technically, XSS involves injecting malicious Javascript, but sometimes you don't need any JS to get up to mischief! 😈
securitytipxssstrictlystill
https://gf.dev/xss-protection-test
Legacy XSS Header Check | GF.dev Geek Tools
Check for the X-XSS-Protection header.
legacyxssheadercheckgf
https://hacks.mozilla.org/2026/02/goodbye-innerhtml-hello-sethtml-stronger-xss-protection-in-firefox-148/
Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148 - Mozilla Hacks - the Web...
Cross-site scripting (XSS) remains one of the most prevalent vulnerabilities on the web. The new standardized Sanitizer API provides a straightforward way for...
protection in firefoxthe webgoodbyehellostronger
Sponsored https://darlink.ai/
DarLink AI: Free AI Girlfriend Generator | Chat, Photos & Video
Create your ideal AI Girlfriend with DarLink AI. Customize her look and personality, chat naturally, and enjoy personalized photos, videos, and voice for a...
https://owasp.org/www-community/attacks/xss/
Cross Site Scripting (XSS) | OWASP Foundation
Cross Site Scripting (XSS) on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.
cross site scriptingxssowaspfoundation
https://extensions.joomla.org/vulnerable-extensions/resolved/convert-forms-4-4-10-xss-cross-site-scripting/
Convert Forms, 4.4.10, XSS (Cross Site Scripting)
Convert Forms, 4.4.10, 3rd party extension
cross site scriptingconvertformsxss
https://www.haproxy.com/glossary/what-is-cross-site-scripting-xss
What is cross-site scripting (XSS)?
Aug 27, 2025 - Cross-site scripting (XSS) attacks inject malicious scripts (or code) into websites that are otherwise trustworthy or seemingly harmless.
cross site scriptingwhat isxss
https://dalfox.hahwul.com/
Dalfox | Dalfox is a powerful open-source XSS scanner and utility focused on automation.
Dalfox is a powerful open-source XSS scanner and utility focused on automation.
open sourcepowerfulxssscannerutility
https://link.springer.com/chapter/10.1007/978-3-319-66399-9_7?error=cookies_not_supported&code=1f577712-504a-41e9-827d-d1671c2acec1
DOMPurify: Client-Side Protection Against XSS and Markup Injection | Springer Nature Link
To prevent Cross-Site Scripting (XSS) and related attacks, sanitation of untrusted content is usually performed either on the server side, or by client-side...
springer nature linkdompurifyclientsideprotection
Sponsored https://dateplayertwo.com/
Date Player 2 | The Gamer Dating Site
Meet your player 2. Effortlessly browse through potential gamers, geeks & cosplayers. It's time to meet local gamers and find your final fantasy! Search by...
https://7asecurity.com/free-workshop-desktop-apps/b
Hacking Modern Desktop apps with XSS and RCE | Blog
Free course or pentest? Join our desktop app hacking workshop with RCE and XSS techniques | Blog. Learn more from 7ASecurity now.
desktop appshackingmodernxssrce
https://extensions.joomla.org/vulnerable-extensions/vulnerable/admirror-gallery-xss-cross-site-scripting/
admirror gallery, , XSS (Cross Site Scripting)
admirror gallery, , 3rd party extension
cross site scriptinggalleryxss
https://extensions.joomla.org/vulnerable-extensions/resolved/hikashop-5-1-1-xss-cross-site-scripting/
HikaShop, 5.1.1, XSS (Cross Site Scripting)
HikaShop, 5.1.1, 3rd party extension
cross site scripting5 1hikashopxss
https://extensions.joomla.org/vulnerable-extensions/resolved/phoca-gallery-5-0-0-xss-cross-site-scripting/
Phoca Gallery, 5.0.0, XSS (Cross Site Scripting)
Phoca Gallery, 5.0.0, 3rd party extension
cross site scriptinggallery 5xss
https://blog.miki.it/posts/xss-in-zagat-xor/
XSS in Zagat, exploiting a XOR-based obfuscation algorithm – Miki's Blog
xssxorbasedobfuscationalgorithm
https://jsoup.org/
jsoup: Java HTML parser, built for HTML editing, cleaning, scraping, and XSS safety
Open source Java HTML parser, with the best of HTML5 DOM methods and CSS selectors, for easy data extraction.
built forjsoupjavahtmlparser
https://extensions.joomla.org/vulnerable-extensions/vulnerable/livingword-xss-cross-site-scripting/
LivingWord, , XSS (Cross Site Scripting)
LivingWord, , 3rd party extension
cross site scriptingxss
https://frederikbraun.de/finding-and-fixing-dom-based-xss-with-static-analysis.html
Frederik Braun: Finding and Fixing DOM-based XSS with Static Analysis
Finding and Fixing DOM-based XSS with Static Analysis
frederik braunstatic analysisfindingfixingdom
https://extensions.joomla.org/vulnerable-extensions/vulnerable/extplorer-2-1-15-xss-cross-site-scripting/
EXTPLORER, 2.1.15, XSS (Cross Site Scripting)
EXTPLORER, 2.1.15, 3rd party extension
cross site scripting2 1xss
https://blog.dragonsector.pl/2017/03/0ctf-2017-complicated-xss-web-177.html
Dragon Sector: 0CTF 2017 - complicated xss (web 177)
Complicated xss was a client-side web security task revolving around, well, XSSes. At the very start you were handed a way to XSS the adm...
dragon sectorcomplicatedxssweb