appsec.fyi

XSS — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

XSS: A Practical Guide

Curated and synthesized by . Last updated 2026-10-01. Synthesized from 380 of 380 curated resources. Browse all 380 XSS resources →

Problem Framing

Cross-Site Scripting (XSS) remains a persistent and high-impact web application vulnerability, enabling attackers to inject malicious scripts into web pages viewed by other users. The core of an XSS attack lies in the improper handling of user-supplied data, allowing it to be interpreted as executable code within the victim's browser context. While the fundamental principles of XSS have been understood for decades, the landscape of exploitation and defense is continually evolving due to advancements in web technologies, browser security features, and attacker methodologies [200][201][328].

XSS vulnerabilities manifest in several primary forms: Reflected XSS, where the malicious script is embedded in a URL or request and reflected back in the immediate response; Stored XSS, where the script is permanently stored on the target server (e.g., in a database or forum post) and served to multiple users; and DOM-based XSS, where the vulnerability lies entirely within client-side JavaScript code, often due to insecure manipulation of the Document Object Model (DOM) [200][260][263]. The impact of XSS can range from trivial defacement and cookie theft to severe consequences like session hijacking, credential exfiltration, credential harvesting via phishing, data exfiltration, account takeover, and even remote code execution (RCE) in certain configurations [340][359]. Modern threats also involve chaining XSS with other vulnerabilities for amplified impact [97].

The proliferation of Single Page Applications (SPAs), complex JavaScript frameworks, and browser extension development has introduced new attack vectors and increased the attack surface for DOM-based XSS [83][84][85]. Furthermore, the increasing use of AI/LLMs in vulnerability discovery and exploitation, along with supply chain attacks targeting third-party libraries, adds further complexity to the XSS threat model [6]. Understanding the nuances of modern web development, browser security features, and the sophisticated evasion techniques employed by attackers is crucial for practitioners tasked with identifying and mitigating these pervasive vulnerabilities.

Core Mechanics of XSS

At its heart, an XSS vulnerability arises when an application fails to properly sanitize or encode user-supplied input before rendering it in a web page. This mishandling allows untrusted data to be injected and executed within the context of a legitimate user's browser session, effectively tricking the browser into treating attacker-controlled content as trusted code.

Input Sanitization and Output Encoding

The primary defense against XSS revolves around two key concepts: input sanitization and output encoding.

The context of the output is critical. Encoding for HTML is different from encoding for JavaScript or CSS. An improperly encoded character in one context might become a vulnerability in another. For example, a character escaped for HTML might still be interpreted as part of a JavaScript string or a CSS property value.

Common Injection Points and Sinks

XSS vulnerabilities can occur in numerous places within a web application:

The "sinks" are the parts of the application where user input is processed and potentially executed. Common sinks include:

Notable Techniques

The variety of XSS techniques is extensive, ranging from basic payload injection to sophisticated bypasses of security mechanisms.

Reflected and Stored XSS

<input type="text" name="q" value="[USER_INPUT]">

If [USER_INPUT] is not encoded, injecting into the q parameter could execute the script.

DOM-based XSS

DOM-based XSS is particularly insidious because the vulnerability resides in client-side JavaScript. The server might be entirely unaware of the exploit. Data from a user-controlled source (e.g., location.hash, location.search, window.name, localStorage) is processed by client-side scripts and written to a dangerous sink (e.g., innerHTML, eval(), document.write()) without proper sanitization [260][263][287].

Advanced Evasion and Bypass Techniques

Attackers frequently employ sophisticated methods to evade Web Application Firewalls (WAFs) and built-in sanitizers.

Context-Specific Exploitation

Chaining and Impact Amplification

XSS is often most dangerous when chained with other vulnerabilities.

Detection and Prevention

Effective XSS detection and prevention require a multi-layered approach, combining robust coding practices with ongoing testing and tooling.

Secure Coding Practices

The most effective defense begins during development.

Detection and Testing

Tooling

A rich ecosystem of tools aids in the detection, exploitation, and prevention of XSS.

Recent Developments

The XSS landscape continues to evolve with new technologies and attack vectors.

Where to Go Deeper

Mastering XSS requires continuous learning and hands-on practice.

Sources cited in this guide

  1. What's in a tag name? JavaScript, apparently — portswigger.net
  2. Full Disclosure: DOM-Based XSS And Failures In Bug Bounty Hunting — kuldeep.io
  3. Intigriti July 2025 XSS Challenge — Jorian Woltjer — jorianwoltjer.com
  4. Bypassing WAFs for Fun and JS Injection with Parameter Pollution — blog.ethiack.com
  5. Bypassing DOMPurify with Good Old XML — flatt.tech
  6. GreHack 2024 | Playing with HTML parsing to bypass DOMPurify on default configuration — slides.com
  7. The Brute Art of Bypass - Unfiltered Edition: Master XSS Filter Evasion — brutelogic.net
  8. Cross Site Scripting (XSS) - Payload Generator | Nettitude Labs — labs.nettitude.com
  9. https://portswigger.net/research/our-favourite-community-contributions-to-the-xss-cheat-sheet — portswigger.net
  10. [tl;dr sec] #341 - Hugging Face Incident Black Hat Talk, CSS Bomb in your Inbox, GitHub Supply Chain Security Improvements — tldrsec.com
  11. CSS:the bomb inside your inbox — portswigger.net
  12. CVE-2025-25461: SeedDMS Stored XSS — github.com
  13. PolyShell flaw exposes Magento and Adobe Commerce to file upload attacks — securityaffairs.com
  14. DOM Purify - dirty namespace bypass — blog.slonser.info
  15. Sniping Insecure Cookies with XSS — breakdev.org
  16. Sniping Insecure Cookies with XSS — breakdev.org
  17. CVE-2026-64638: Critical Pre-Auth XSS Vulnerability in WordPress Allows Remote Code Execution — rescana.com
  18. CVE-2025-66412: Angular Stored XSS via SVG Animation and MathML Attributes — github.com
  19. FortiSandbox XSS Vulnerability Allows Remote Command Execution — esecurityplanet.com
  20. Finding DOM Polyglot XSS in PayPal the Easy Way — portswigger.net
  21. Beyond alert(1): Real XSS Dangers in React & Vue SPAs — instatunnel.my
  22. PortSwigger Web Security Blog: XSS without HTML: Client-Side Template Injec — blog.portswigger.net
  23. UltimateHackers/XSStrike: XSS Scanner equipped with powerful fuzzing engine — github.com
  24. Blind XSS for beginners — medium.com
  25. Finding and Fixing DOM-based XSS with Static Analysis Attack & Defense — blog.mozilla.org
  26. Hunting Blind XSS on the Large Scale — Practical Techniques — ott3rly.com
  27. Mass Hunting Blind XSS Using XSSHunter Express Part 1 — ott3rly.com
  28. The XSS hunter's secret weapon — bxsshunter.com
  29. Hacker Tools: How to set up XSSHunter — blog.intigriti.com
  30. Introducing DOM Invader: DOM XSS just got a whole lot easier to find — portswigger.net
  31. GitHub - Cybersecurity-Ethical-Hacker/xssdynagen: 🪄 XSSDynaGen is a tool designed to analyze URLs with parameters, identify the characters allowed by the server, and generate advanced XSS payloads based on the analysis results. — github.com
  32. XSS Hunter is Now Open Source Heres How to Set It Up! — thehackerblog.com
  33. Simplifying XSS Detection with Nuclei - A New Approach — blog.projectdiscovery.io
  34. s0md3v/AwesomeXSS — github.com
  35. Cross-Site Scripting (XSS) Cheat Sheet - 2023 Edition | Web Security Academ — portswigger.net
  36. Cross Site Scripting - Payloads All The Things — swisskyrepo.github.io
  37. https://github.com/terjanq/Tiny-XSS-Payloads — github.com
  38. JS-Tap: Weaponizing JavaScript for Red Teams — trustedsec.com
  39. Security Issues in Popular Full-Stack Frameworks — kodemsecurity.com
  40. https://blog.isiraadithya.com/intigriti-1021-xss-challenge-solution-writeup/ — blog.isiraadithya.com
  41. Sourcehut account takeover via build logs (XSS in ansi2html) — blog.arusekk.pl
📚 This guide is synthesized from the full text of resources curated in the XSS library, and refreshed as new material is added.