appsec.fyi

Cross-Site Scripting (XSS) Resources

Post Share

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS) attacks are a type of injection in which malicious scripts are injected into otherwise benign and trusted websites. XSS occurs when an attacker uses a web application to send malicious code, generally in the form of a browser-side script, to a different end user.

XSS remains one of the most prevalent web vulnerabilities, appearing in everything from search bars to user profile fields. The three main variants — Reflected, Stored, and DOM-based — each have distinct attack surfaces. Reflected XSS executes via a crafted URL, Stored XSS persists in the application's database and fires for every visitor, and DOM-based XSS exploits client-side JavaScript that unsafely handles user input without any server round-trip.

The impact of XSS extends well beyond simple alert boxes. Attackers leverage it for session hijacking, credential theft, keylogging, phishing overlays, and as a pivot point for deeper exploitation. In bug bounty programs, Stored XSS on authenticated pages consistently pays well because it can be chained into account takeover.

Modern defenses include Content Security Policy (CSP), output encoding, and frameworks that auto-escape by default — but bypasses are discovered regularly, making XSS a constantly evolving attack surface.

This page collects research, bypass techniques, payloads, and real-world writeups covering all forms of cross-site scripting.

From OWASP

Read the XSS guideA long-form, source-cited deep dive synthesized from every resource below. The comprehensive XSS guide on chs.usA hand-written, in-depth practitioner guide — attacks, testing, and prevention.
Date Added Link Excerpt
2026-08-09 NEW 2026CVE-2026-64638: Critical Pre-Auth XSS Vulnerability in WordPress Allows Remote Code Execution newsA critical pre-authentication Cross-Site Scripting (XSS) vulnerability, CVE-2026-64638, has been discovered in WordPress. This flaw allows remote attackers to execute arbitrary code on affected systems without requiring any user authentication. The vulnerability poses a significant security risk to WordPress websites. → rescana.com
2026-08-09 NEW 2026High-Severity WordPress Vulnerability Affects All Versions Could Lead to Admin Account Takeover news 4 min readWriteup of CVE-2026-64638, a pre-authentication reflected XSS on the WordPress login page, enabling attackers to achieve PHP code execution via an "XSS2Shell" attack chain that leverages Application Passwords and Same Origin Method Execution (SOME). This vulnerability, discovered by pwn.ai, affects all WordPress versions and can lead to admin account takeover, website hijacking, and arbitrary code execution. WordPress has released emergency patches.
2026-08-07 NEW 2026PimpMyCaido #1: Hunt client-side vulnerabilities with DOMLogger++ intermediate MobileThis content introduces PimpMyCaido #1, a guide focused on finding client-side vulnerabilities. It specifically highlights the use of a tool called DOMLogger++ for this purpose. The title suggests a practical, hands-on approach to security testing within web applications, emphasizing techniques for uncovering weaknesses accessible from the user's browser. → yeswehack.com
2026-08-07 NEW 2026CSS:the bomb inside your inbox intermediate 37 min readAnalysis of CSS sanitization bypass techniques, demonstrating novel methods to exfiltrate tokens, compromise third-party websites, and steal passwords by exploiting discrepancies between browser rendering and sanitizer interpretation. Techniques discussed include abusing HTML `<label>` elements for UI control in Outlook and employing `:before` and `:after` pseudo-elements with opacity manipulation to achieve indirect prompt injection in OpenAI's Atlas browser, targeting webmail clients like Yahoo Mail, AOL Mail, Fastmail, ProtonMail, GMail, and Outlook. → portswigger.net
2026-08-06 NEW 2026Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920) intermediate 8 min readWriteup of CVE-2026-15920, detailing a stored XSS vulnerability in Django's admin. This flaw occurs when URLField values are displayed as clickable links without proper validation, allowing attacker-controlled `javascript:` URIs to execute arbitrary code within an authenticated staff session. The vulnerability stems from a coding oversight where the `FileField` branch's structure was copied for `URLField` without retaining necessary scheme checks. This bypasses standard validation, as many write paths do not invoke `full_clean()`, making it possible to inject malicious data directly into the database.
2026-08-02 NEW 2026Russian hackers exploit unpatched Zimbra servers to steal emails news 2 min readWriteup of CVE-2025-66376, a cross-site scripting vulnerability in Zimbra Collaboration Suite exploited by Russian hacker group Laundry Bear to steal emails and sensitive data from government and commercial networks. The attack weaponizes specially crafted HTML emails, requiring only viewing to execute JavaScript, enabling the theft of account data, authentication tokens, and application passcodes. Laundry Bear has also been observed using AI in the development of their infrastructure for data exfiltration. → helpnetsecurity.com
2026-07-31 2026Looker 26.12 Turns MFA On by Default and Closes Known XSS Vulnerability news 9 min readLibrary for application security, Looker 26.12 enforces multi-factor authentication by default for email/password logins and patches CVE-2026-15810, a cross-site scripting vulnerability that could hijack administrator accounts. Self-hosted instances require manual patching from specific release branches. The update also graduates the Gemini-powered Expression Assistant, Custom Calendar, and Enhanced Search to general availability, alongside adding per-status email alerting to Looker Continuous Integration. → techtimes.com
2026-07-28 2026How I Found a Bug Worth $3,500 — In a Feature Nobody Was Watching. intermediate 6 min read Bug Bounty RCEWriteup detailing a $3,500 bounty discovery involving a file upload form on a B2B SaaS platform. The exploit chained a CWE-434 and CWE-770 storage exhaustion flaw, achievable by spoofing file size metadata, with a CWE-79 critical stored XSS in the filename that executed in an admin's browser. The analysis highlights the importance of scrutinizing metadata, understanding victim context for severity, testing "boring" features, and chaining vulnerabilities. → infosecwriteups.com
2026-07-27 2026Eight NodeBB Vulnerabilities Let Hackers Read Your Private Chats and Take Over the Forum newsEight critical vulnerabilities discovered in NodeBB forum software could allow attackers to read private messages and gain administrative control of forums. These flaws, detailed in a recent report, pose a significant security risk to users and forum administrators. The exact payout for discovering these vulnerabilities was not stated. → cybersecuritynews.com
2026-07-24 2026Russian Global Webmail Espionage intermediate 3 min read AuthNAnalysis of CL-STA-1114, a cyberespionage campaign by Void Blizzard/LAUNDRY BEAR, details exploitation of CVE-2025-66376 in Zimbra Collaboration Suite. This zero-click vulnerability in ZCS webmail allows a malicious JavaScript payload injection via HTML attachments or embedded HTML, exfiltrating credentials, 2FA codes, email archives, and search histories. The campaign targets governments, defense, transportation, and financial organizations in NATO states, Ukraine, CIS, and Africa. → unit42.paloaltonetworks.com
2026-07-23 2026Finding eight high-severity vulnerabilities in NodeBB in six hours intermediate 19 min read AuthZ Bug BountyWriteup detailing eight high-severity vulnerabilities discovered in NodeBB versions prior to 4.14.0, including Cross-Site Scripting (XSS) exploiting custom Federation servers and template injection. The writeup specifies a template injection impacting nearly all inputs and authorization bypasses allowing data hijacking. The analysis highlights how autonomous agents achieved these findings within hours, leading to prompt fixes by NodeBB maintainers. → aikido.dev
2026-07-22 2026Rickrolling the World Cup, unleashing AI across Google, 0-click stored XSS on Next.js – ethical hacker roundup newsThis roundup highlights significant cybersecurity events: an ethical hacker managed to "rickroll" the World Cup, while another discovered a 0-click stored XSS vulnerability in Next.js. Additionally, the piece touches upon the widespread implementation of AI across Google's services, implying potential security considerations and ethical discussions surrounding its deployment. → yeswehack.com
2026-07-21 2026Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities news 1 min readLibrary for patching Zimbra vulnerabilities, including a critical SNMP command injection flaw and four XSS vulnerabilities in the Classic Web Client. The XSS flaws involve stored XSS via malicious attachment filenames, crafted fields executing script, and crafted attachments rendering script. Additionally, it addresses CVE-2026-50055, a mail forwarding restriction bypass allowing email exfiltration. → thehackernews.com
2026-07-18 2026SAR 2,629 For Stored XSS via svg Image Leading to ATO intermediate 2 min readWriteup detailing a Stored XSS vulnerability found via profile picture uploads, enabling Account Takeover (ATO). Exploiting a missing Content Security Policy (CSP) and same-origin hosting of SVG images allowed for the execution of injected JavaScript. This script accessed and exfiltrated authentication tokens stored in `localStorage`, granting full control of the user account without needing credentials. Remediation involves SVG sanitization, strict CSP implementation, and enforcing `Content-Disposition: attachment`. → infosecwriteups.com
2026-07-14 2026Zimbra urges customers to patch critical web client XSS flaw news 2 min readVulnerability details Zimbra's critical stored XSS flaw in its Classic Web Client, which allows attackers to execute malicious code via crafted emails, potentially stealing session data and mailbox information. This zero-day was reported by Google's Threat Analysis Group and has been actively exploited in the past by Russian state-sponsored groups like Winter Vivern and APT29 against high-risk individuals and organizations. While a CVE ID is pending, this highlights the ongoing threat to Zimbra instances, following previous patches for similar XSS vulnerabilities like CVE-2025-66376 and CVE-2025-48700. → bleepingcomputer.com
2026-07-11 2026Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions news 1 min readLibrary update addressing stored XSS in Zimbra Classic Web Client. Exploitation of this vulnerability allows attackers to inject and execute malicious JavaScript within user sessions via crafted emails, potentially leading to mailbox access, session data compromise, and account setting manipulation. This flaw, though unassigned a CVE, follows a history of XSS vulnerabilities in Zimbra, including CVE-2025-27915, CVE-2023-37580, and CVE-2024-27443. Users are advised to update to Zimbra Collaboration Suite version 10.1.19. → thehackernews.com
2026-07-11 2026Zimbra 10.1.19 Fixes Stored XSS Flaw Triggered by Crafted Emails newsZimbra 10.1.19 addresses a stored cross-site scripting (XSS) vulnerability that could be exploited by sending specially crafted emails. This flaw allowed attackers to inject malicious scripts into the Zimbra web client, potentially leading to unauthorized actions or data theft by users who viewed the compromised email. The update rectifies this security weakness, enhancing the platform's safety. → cyberpress.org
2026-07-10 2026Roundcube Webmail Security Update Patches Critical Zero-Click XSS and SSRF Bypass Flaws newsRoundcube Webmail has released a security update addressing critical zero-click vulnerabilities. These flaws allowed for Cross-Site Scripting (XSS) and Server-Side Request Forgery (SSRF) bypasses, potentially enabling attackers to execute malicious code or access internal resources without user interaction. Users are strongly advised to update their Roundcube installations immediately to mitigate these risks. The update is crucial for protecting against potential exploitation of these severe security weaknesses. → gbhackers.com
2026-07-09 2026Roundcube 0-Click Vulnerability Enables Stored XSS Attack via MIME Type Attachment intermediateA critical 0-click vulnerability in Roundcube allows stored XSS attacks through specially crafted MIME type attachments. Attackers can exploit this by sending an email with an attachment having a malicious MIME type. When Roundcube processes this attachment, it renders the malicious content, leading to cross-site scripting execution within the victim's browser without any user interaction. This means sensitive data could be compromised or actions taken on behalf of the user. → cybersecuritynews.com
2026-07-08 2026Chaining a DOM XSS Sink, WAF Bypass, Cross-Origin Smuggling, and SDK Abuse into One Click Account… advanced 8 min read API Sec AuthNLibrary for chaining DOM XSS, WAF bypass via `window.name` cross-origin smuggling, and SDK abuse to achieve one-click account takeover. The technique exploits a `javascript:` URL sink, bypasses Akamai's WAF by inserting characters between keywords and parentheses, leverages `window.name` persistence across navigations, and abuses a first-party authentication SDK to retrieve signed JWTs and live AWS STS credentials. → infosecwriteups.com
2026-07-06 2026Multiple IBM WebSphere Vulnerabilities Enable XSS and Path Traversal Attacks intermediateMultiple vulnerabilities have been discovered in IBM WebSphere that could allow attackers to perform cross-site scripting (XSS) and path traversal attacks. These flaws impact various versions of the software, potentially exposing sensitive data and enabling malicious code execution. Organizations using IBM WebSphere should prioritize applying the latest security patches and updates to mitigate these risks. → cybersecuritynews.com
2026-07-06 2026IBM WebSphere Application Server Hit by Critical XSS and Path Traversal Vulnerabilities newsIBM WebSphere Application Server is affected by critical vulnerabilities. These include Cross-Site Scripting (XSS) and path traversal flaws. The XSS vulnerability allows attackers to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking or data theft. The path traversal vulnerability could enable unauthorized access to sensitive files and directories on the server. Organizations using IBM WebSphere Application Server should update to the latest secure versions to mitigate these risks. → gbhackers.com
2026-07-06 2026Critical IBM WebSphere Flaws Expose Servers to XSS and Path Traversal Attacks newsCritical vulnerabilities have been discovered in IBM WebSphere Application Server, enabling attackers to execute Cross-Site Scripting (XSS) and path traversal attacks. These flaws could allow for unauthorized access to sensitive data and the execution of malicious code on vulnerable servers. Organizations utilizing IBM WebSphere are strongly advised to apply available security patches and updates to mitigate these risks and protect their environments. Further details on the specific vulnerabilities and remediation steps can be found at the provided link. → cyberpress.org
2026-07-05 2026Attackers Can Inject Malicious Scripts Through VMware XSS Flaws beginnerVMware products are vulnerable to Cross-Site Scripting (XSS) attacks, allowing attackers to inject malicious scripts. This means unauthorized users could potentially execute harmful code within a user's browser session, leading to various security risks like data theft or account compromise. Further details and the specific impact are outlined in the provided link. → cyberpress.org
2026-07-01 2026Critical Webmin Vulnerabilities Allow Attackers to Impersonate as Any User newsCritical Webmin Vulnerabilities Allow Attackers to Impersonate as Any User https://ift.tt/J5oKeT4 → cybersecuritynews.com
2026-06-29 2026CVE-2026-13536: Reflected XSS Vulnerability in GotoHTTP Remote Access Platform (reg.12x Endpoint) Analysis and Mitigation intermediate 3 min readAnalysis of CVE-2026-13536 details a reflected XSS vulnerability in the GotoHTTP remote access platform's /reg.12x endpoint, stemming from improper sanitization of the sn parameter. This allows unauthenticated attackers to inject JavaScript via crafted URLs, with a public PoC available on GitHub. While no active exploitation by APT groups is reported, and it's not on the CISA KEV catalog, opportunistic attacks are a risk due to the low complexity and user interaction requirement. The vendor has acknowledged the issue and will remove the vulnerable parameter in their next release. → rescana.com
2026-06-25 2026CVE-2026-10086: High-Severity XSS Vulnerability in GitLab Enterprise Edition Analytics Dashboard Analysis Impact and Mitigation Steps news 3 min readAnalysis of CVE-2026-10086, a high-severity XSS vulnerability in GitLab Enterprise Edition's Analytics Dashboard, details how authenticated attackers can inject JavaScript. This vulnerability, CWE-79, allows for session hijacking and privilege escalation by executing code in user contexts. Patched versions include 19.1.1, 19.0.3, and 18.11.6. While not yet observed in the wild, prompt patching and log review are advised, with potential mitigation by restricting dashboard access. → rescana.com
2026-06-24 2026Webmin Stored XSS Vulnerability Lets Attackers Exploit Root Users newsA stored cross-site scripting (XSS) vulnerability has been discovered in Webmin, a web-based system administration tool. This flaw allows attackers to inject malicious scripts into the application, which can then be executed by other users, including those with root privileges. Successful exploitation could lead to unauthorized actions on the server, data theft, or complete system compromise. Users are strongly advised to update their Webmin installations to patch this critical security issue. → gbhackers.com
2026-06-24 2026Critical Webmin Stored XSS Vulnerability Lets Untrusted Users Exploit Root Accounts intermediateCritical Webmin Stored XSS Vulnerability Lets Untrusted Users Exploit Root Accounts https://ift.tt/8gMoQkc → cyberpress.org
2026-06-23 2026CVE-2026-25860 turn XSS to RCE intermediateCVE-2026-25860 turn XSS to RCE
2026-06-23 2026Exploring WebExtension security vulnerabilities in React Developer Tools and Vue.js devtools intermediate 5 min read Bug BountyWriteup detailing WebExtension security vulnerabilities, including unverified external messages in React Developer Tools (CVE-2023-5654) allowing arbitrary URL fetching and unauthorized access to page capture APIs in Vue.js devtools (CVE-2023-5718) leading to screenshot data leakage. This research highlights risks inherent in the WebExtension architecture and its components, affecting cross-browser compatibility and user data. → snyk.io
2026-06-22 2026Exploiting Auth0 Defaults in XSS Attacks - elttam intermediate 8 min read AuthNWriteup detailing how XSS vulnerabilities in applications using Auth0 can be exploited. The article highlights the insecure implicit grant flow, enabled by default in Auth0, and demonstrates how it can be combined with other misconfigurations to pivot across tenant applications. Specifically, it shows how an attacker can leverage XSS to steal access tokens intended for a protected API, facilitating lateral movement within an Auth0 tenant. → elttam.com
2026-06-21 2026Understanding and mitigating the Jinja2 XSS vulnerability (CVE-2024-22195) intermediate 3 min read PythonReference detailing CVE-2024-22195, a cross-site scripting vulnerability in Jinja2 versions prior to 3.1.3. The vulnerability arises from the `xmlattr` filter when processing user input with spaces in keys, allowing attackers to inject arbitrary HTML attributes and potentially execute untrusted scripts. Mitigation involves upgrading to Jinja2 3.1.3 and utilizing tools like Snyk for continuous monitoring and detection of vulnerable dependencies in Python projects and Docker containers. → snyk.io
2026-06-20 2026“Bug Bounty Bootcamp #48: OAuth + XSS ” intermediate AuthN Bug BountyThis "Bug Bounty Bootcamp #48" article, titled "OAuth + XSS," explores a potent combination of vulnerabilities: OAuth and Cross-Site Scripting (XSS). The content suggests that by leveraging these two, attackers can achieve account takeovers, effectively describing it as an "ultimate account takeover one-two punch." The article is part of a series and can be found on InfoSec Write-ups. No specific bounty payout amount is mentioned. → infosecwriteups.com
2026-06-19 2026Microsoft's Exchange Server Updates Fix OWA XSS Flaw news 2 min readLibrary update for Microsoft Exchange Server addresses CVE‑2026‑42897, a cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA). This flaw allows remote attackers to execute malicious JavaScript by sending specially crafted emails. Updates are available for Exchange Server Subscription Edition, 2019, and 2016, with support requirements for older versions. Administrators should use the Exchange Health Checker script and install the latest cumulative and security updates. → petri.com
2026-06-17 2026How to prevent log injection vulnerability in JavaScript and Node.js applications intermediate 6 min readLibrary for preventing log injection vulnerabilities in JavaScript and Node.js applications, specifically detailing how attackers can manipulate input to inject malicious code into logs. It offers methods for sanitizing user inputs, using regex and libraries like validator.js, suggests careful consideration of what data to log, and recommends structured logging and specialized libraries such as pino over basic console.log. The entry also mentions the Snyk IDE extension for VS Code as a tool for detecting such vulnerabilities. → snyk.io
2026-06-16 2026Automatically fix code vulnerabilities with AI intermediate 4 min read AILibrary for automatically fixing common security vulnerabilities, such as Cross-site Scripting (XSS) in Java applications, by leveraging a hybrid AI model. This tool, integrated into IDEs, goes beyond providing remediation advice by directly applying secure code fixes, exemplified in a Spring Boot application using the Thymeleaf template engine and the faker library. Unlike generative AI assistants that may introduce insecure code, this library uses a combination of generative AI, symbolic AI, and machine learning, trained on curated security research data, to ensure secure code generation. → snyk.io
2026-06-14 2026MeshCentral: From XSS to RCE intermediate 8 min read RCEWriteup detailing the exploitation of MeshCentral, moving from Cross-Site Scripting (XSS) to Remote Code Execution (RCE). The author demonstrates how an LLM, Claude Opus, was utilized to identify vulnerabilities and generate proof-of-concept exploits by analyzing the MeshCentral agent and server interactions. The process involved extracting agent credentials from local files to impersonate existing agents and ultimately achieve RCE, showcasing a practical application of AI in vulnerability research.
2026-06-13 2026Six levels, one lesson: LLMs cannot keep a secret intermediate AIGitHub's Secure Code Game Season 3, a six-level challenge, demonstrates that Large Language Models (LLMs) cannot keep secrets. The game involves prompt injection attacks against vulnerable AI assistants designed to hide information. Players craft attacks to extract these secrets, highlighting that system prompts are not a security measure. The content focuses on hands-on learning of AI security principles through this open-source, browser-based game. No bounty payout amounts are mentioned. → infosecwriteups.com
2026-06-12 2026Chaining Stored XSS and CSRF in Typemill CMS: A Deep Dive into Attribute Injection intermediate CSRFA security assessment of Typemill CMS uncovered a critical vulnerability chain combining Stored XSS and CSRF (CVE-2026–53468). An attacker can bypass frontend validation to inject malicious scripts into page metadata. This allows for the theft of admin sessions by exploiting attribute injection. This vulnerability impacts Typemill, a popular flat-file CMS built on PHP and the Slim framework, and poses a significant risk to its users. → infosecwriteups.com
2026-06-10 2026Microsoft patches Exchange Server zero-day exploited in attacks news 2 min readPatching advisory for CVE-2026-42897 details a critical spoofing vulnerability in Microsoft Exchange Server 2016, 2019, and SE. Exploitable remotely without privileges, it allows arbitrary JavaScript execution via specially crafted emails opened in Outlook Web Access. Microsoft urges immediate deployment of June 2026 Security Updates. CISA has added this actively exploited flaw to its known exploited vulnerabilities catalog, mandating swift patching for U.S. government agencies. → bleepingcomputer.com
2026-06-08 2026Multiple VMware Stored XSS Flaw Enable Attackers to Inject Malicious Scripts newsVMware products are affected by multiple stored cross-site scripting (XSS) vulnerabilities. These flaws allow attackers to inject and execute malicious scripts within the affected applications. Successful exploitation could lead to various security risks, including session hijacking, data theft, and unauthorized actions on behalf of users. Users are advised to consult VMware's security advisories for specific product and version information and to apply any available patches or workarounds promptly to mitigate these risks. → gbhackers.com
2026-06-08 2026Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts newsVMware has addressed several stored cross-site scripting (XSS) vulnerabilities across its products. These flaws could enable attackers to inject malicious scripts into web applications, potentially leading to unauthorized access, data theft, or other harmful actions. The vulnerabilities were found in specific components of VMware's offerings, allowing for persistent script execution. Users are advised to update their VMware products to the latest versions to mitigate these security risks. The provided link offers detailed information on the affected products and the specific CVEs associated with these vulnerabilities. → cybersecuritynews.com
2026-06-08 2026JavaScript Prototype Pollution Deep Dive : — Reconnaissance, Exploitation & Bug Bounty Guideline advanced RCEThis article provides a deep dive into JavaScript Prototype Pollution vulnerabilities, explaining the underlying prototype chain and its attack vectors. It covers reconnaissance methodologies, exploitation techniques ranging from XSS to Remote Code Execution (RCE), and real-world bug bounty case studies. The guide also delves into advanced exploit chains, tooling, automation, and defense strategies, offering a production-ready Python scanner. The content focuses on understanding and mitigating this complex JavaScript vulnerability. → infosecwriteups.com
2026-06-08 2026From XSS to RCE (dompdf 0day) intermediate 10 min read RCELibrary for Remote Code Execution (RCE) in dompdf, a popular PHP library used for rendering PDFs from HTML. The vulnerability, identified as a 0-day by Positive Security, allows an attacker to inject CSS that tricks dompdf into caching a malicious font file with a `.php` extension. This file can then be executed remotely by accessing it from the web server. The exploit leverages the `$isRemoteEnabled` setting and the font caching mechanism within dompdf.
2026-06-04 2026Cisco Webex Meetings Cross-Site Scripting Vulnerability (CVE-2026-20233) newsWriteup of CVE-2026-20233, a cross-site scripting (XSS) vulnerability in Cisco Webex Meetings. The flaw stemmed from insufficient user input validation, allowing an unauthenticated remote attacker to execute arbitrary script code or access sensitive browser information by tricking a user into clicking a malicious link. Cisco has resolved this issue in their cloud-based Webex Meetings service, requiring no customer action. → systemtek.co.uk
2026-06-03 2026Zero-Click pretalx XSS Flaw Lets Hackers Hijack Conference Organizer Accounts intermediate 2 min readLibrary for detecting stored XSS vulnerabilities, exemplified by CVE-2026-41241 in pretalx, which allows zero-click account hijacking. This flaw, exploitable with low privileges, bypasses Content Security Policies by leveraging chained exploits involving JavaScript payloads disguised as presentation materials and iframe `srcdoc` attributes. A secondary JavaScript-free technique demotes administrators via image tags in submission titles, triggering a superuser-demotion endpoint. Automated AI agents can weaponize this for mass exploitation across numerous conferences. → hackread.com
2026-06-03 2026https://github.com/Armur-Ai/Pentest-Swarm-AI beginner 6 min read AI ReconLibrary for advanced penetration testing utilizing a real swarm intelligence architecture. It coordinates independent agents via stigmergy and emergence, allowing them to coordinate by writing to and reading from a shared blackboard, rather than through a central planner. This approach enables emergent attack chains and dynamic agent interaction, supporting tools like nmap, sqlmap, Burp, ZAP, and Metasploit, and is compatible with LLMs such as Claude and Llama.
2026-06-03 2026House committee chair calls on Instructure to testify in Canvas hack news 3 min readWriteup on the Shiny Hunters attack on Instructure's Canvas platform, highlighting cross-site scripting (XSS) vulnerabilities exploited to hijack admin sessions and exfiltrate student data. The incident prompted a US House committee inquiry, emphasizing the continued relevance of foundational security flaws like input validation and output encoding in critical educational technology infrastructure, despite focus on novel AI threats. → scworld.com
2026-05-28 2026CVE-2026-41241: Critical Stored XSS in Pretalx Conference Platform Allows Attackers 100% Talk Acceptance (Patched in 2026.1.0) news 5 min readWriteup of CVE-2026-41241, a critical stored XSS vulnerability in Pretalx versions prior to 2026.1.0, allowing any registered user to compromise organizer accounts and force talk acceptance. Exploitation involves submitting a talk proposal with a crafted XSS payload in fields like title, speaker display name, or email, which executes when an organizer uses the backend search. The vulnerability stems from improper sanitization and unsafe `innerHTML` usage. Immediate upgrade to version 2026.1.0 is recommended. → rescana.com

Frequently Asked Questions

What are the three types of XSS?
The three main types are Reflected XSS (payload delivered via a URL and immediately reflected in the response), Stored XSS (payload persisted in the application database and served to other users), and DOM-based XSS (payload executed entirely in the browser via client-side JavaScript without a server round-trip).
How do you prevent cross-site scripting?
Key defenses include output encoding (HTML, JavaScript, URL, and CSS contexts), Content Security Policy (CSP) headers, using frameworks that auto-escape by default (React, Angular), input validation, and the HttpOnly flag on session cookies to limit the impact of successful attacks.
Why is XSS still so common?
XSS persists because web applications have many injection points (URL parameters, form fields, headers, file uploads), developers must encode output correctly for every context, and modern JavaScript frameworks can be bypassed through dangerouslySetInnerHTML, template injection, or prototype pollution.

Weekly AppSec Digest

Get new resources delivered every Monday.