Client-Side
XSS, CSRF and everything that runs in somebody else's browser.
Changing an email with a single GET
Make a logged-in victim's browser send a state-changing request.
Reflected in the search box
Get your script to run in another visitor's browser on this origin.
The error page that echoes your input
Get your script to run in another visitor's browser on this origin.
A comment field that renders markdown too eagerly
Get your script to run in another visitor's browser on this origin.
A JSON endpoint that accepts form content-type
Make a logged-in victim's browser send a state-changing request.
Breaking out of an HTML attribute
Get your script to run in another visitor's browser on this origin.
Stored in a display name
Get your script to run in another visitor's browser on this origin.
The form with no anti-forgery token
Make a logged-in victim's browser send a state-changing request.
Defeating a predictable token
Make a logged-in victim's browser send a state-changing request.
DOM XSS through the URL fragment
Get your script to run in another visitor's browser on this origin.
Injecting into a JSON block the page evaluates
Get your script to run in another visitor's browser on this origin.
SameSite is not set, and it matters
Make a logged-in victim's browser send a state-changing request.
Slipping past a naive filter
Get your script to run in another visitor's browser on this origin.
Login CSRF into an attacker's account
Make a logged-in victim's browser send a state-changing request.
Mutation XSS the sanitiser did not expect
Get your script to run in another visitor's browser on this origin.
Stealing a session under a weak CSP
Get your script to run in another visitor's browser on this origin.