Simple reflected XSS vulnerability where unencoded HTML context allows direct JavaScript execution via a <script> payload.
-
Updated
Nov 15, 2025
Simple reflected XSS vulnerability where unencoded HTML context allows direct JavaScript execution via a <script> payload.
Proof-of-concept XSS scanner using ML to predict execution context and craft targeted payloads.
Advanced Cross-Site Scripting (XSS) vulnerability testing framework with WAF bypass, DOM XSS detection, and comprehensive reporting capabilities.
MAL-012: Reflected Cross-Site Scripting in Admin Console leading to Remote Code Execution in Payara Server
CVE-2019-1332: Reflected Cross-Site Scripting in Microsoft SQL Server Reporting Services
An issue was discovered in cPanel before 11.109.9999.116. Cross-Site Scripting can occur on the cpsrvd error page via an invalid webcall ID.
Exploited a Reflected XSS vulnerability to inject a client-side keylogger payload. Implemented an instant JavaScript redirect to mask the attack and successfully exfiltrate simulated credit card information to a Netcat listener.
Add a description, image, and links to the reflected-xss topic page so that developers can more easily learn about it.
To associate your repository with the reflected-xss topic, visit your repo's landing page and select "manage topics."