Pasindu's Blog
Search
Search
Dark mode
Light mode
Explorer
Home
❯
PortSwigger Labs
❯
Cross site scripting
Cross-site scripting
Jun 22, 2026
1 min read
Cross-site Scripting - PortSwigger Practice Lab
24 items under this folder.
Jul 05, 2026
DOM XSS in AngularJS expression with angle brackets and double quotes HTML-encoded
PortSwigger
Jul 05, 2026
DOM XSS in document.write sink using source location.search inside a select element
PortSwigger
Jul 05, 2026
DOM XSS in document.write sink using source location.search
PortSwigger
Jul 05, 2026
DOM XSS in innerHTML sink using source location.search
PortSwigger
Jul 05, 2026
DOM XSS in jQuery anchor href attribute sink using location.search source
PortSwigger
Jul 05, 2026
DOM XSS in jQuery selector sink using a hashchange event
PortSwigger
Jul 05, 2026
Exploiting XSS to bypass CSRF defenses
PortSwigger
Jul 05, 2026
Reflected DOM XSS
PortSwigger
Jul 05, 2026
Reflected XSS in canonical link tag
PortSwigger
Jul 05, 2026
Reflected XSS into HTML context with all tags blocked except custom ones
PortSwigger
Jul 05, 2026
Reflected XSS into HTML context with most tags and attributes blocked
PortSwigger
Jul 05, 2026
Reflected XSS into HTML context with nothing encoded
PortSwigger
Jul 05, 2026
Reflected XSS into a JavaScript string with angle brackets HTML encoded
PortSwigger
Jul 05, 2026
Reflected XSS into a JavaScript string with angle brackets and double quotes HTML-encoded and single quotes escaped
PortSwigger
Jul 05, 2026
Reflected XSS into a JavaScript string with single quote and backslash escaped
PortSwigger
Jul 05, 2026
Reflected XSS into a template literal with angle brackets, single, double quotes, backslash and backticks Unicode-escaped
PortSwigger
Jul 05, 2026
Reflected XSS into attribute with angle brackets HTML-encoded
PortSwigger
Jul 05, 2026
Reflected XSS with AngularJS sandbox escape and CSP
PortSwigger
Jul 05, 2026
Reflected XSS with AngularJS sandbox escape without strings
PortSwigger
Jul 05, 2026
Reflected XSS with some SVG markup allowed
PortSwigger
Jul 05, 2026
Stored DOM XSS
PortSwigger
Jul 05, 2026
Stored XSS into HTML context with nothing encoded
PortSwigger
Jul 05, 2026
Stored XSS into anchor href attribute with double quotes HTML-encoded
PortSwigger
Jul 05, 2026
Stored XSS into onclick event with angle brackets and double quotes HTML-encoded and single quotes and backslash escaped
PortSwigger