The Lab Universe
Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.
Reflected in the search box
Get your script to run in another visitor's browser on this origin.
The error page that echoes your input
Get your script to run in another visitor's browser on this origin.
A comment field that renders markdown too eagerly
Get your script to run in another visitor's browser on this origin.
Breaking out of an HTML attribute
Get your script to run in another visitor's browser on this origin.
Stored in a display name
Get your script to run in another visitor's browser on this origin.
DOM XSS through the URL fragment
Get your script to run in another visitor's browser on this origin.
Injecting into a JSON block the page evaluates
Get your script to run in another visitor's browser on this origin.
Slipping past a naive filter
Get your script to run in another visitor's browser on this origin.
Mutation XSS the sanitiser did not expect
Get your script to run in another visitor's browser on this origin.
Stealing a session under a weak CSP
Get your script to run in another visitor's browser on this origin.