Vulnerability field guide
Cross-Site Scripting
Cross-site scripting lets attacker-controlled input run as JavaScript in a victim's browser. Here is what XSS is, how its three variants differ, and the layered defense that shuts all of them down.
6 articles 24 min total Overview to advanced techniques
Cross-Site Scripting techniques
5 focused deep-dives
- 02 BlindBlind XSS: When Your Payload Fires in an Admin Panel You Never See
- 03 DOM-BasedDOM-Based XSS: When the Vulnerability Never Touches the Server
- 04 Mutation (mXSS)Mutation XSS (mXSS): How the Browser's Parser Rewrites Your Sanitized HTML
- 05 ReflectedReflected XSS: How a URL Can Run Code in Someone Else's Browser
- 06 StoredStored XSS: One Injection, Every Visitor