xss-test-s15 / README.md
FIRSTACCOUNT69's picture
Update
576f2dd verified
metadata
language: en
license: mit

Advanced XSS

T1: mXSS via noscript

T2: mXSS via math

T3: mXSS via svg/foreignObject

T4: DOMPurify bypass via namespace confusion

T5: DOMPurify bypass via use

T6: CSS injection

test

CSS exfil

T7: Custom protocol handler

HF Protocol

T8: Form with formaction

T9: Anchor with data URI

Click

T10: Template literal

T11: Markdown link tricks

test [test](https://evil.com" onclick="alert(11))