#XSS
December 3, 2024 at 1:16 PM
<script>alert(‘XSS injection tonight queen??’)</script>
November 9, 2025 at 3:41 AM
Additionally, it is vulnerable to XSS
October 8, 2023 at 9:55 PM
一步一步被 @xss-cum.bsky.social 调教强制闻自己的球鞋
December 3, 2024 at 11:50 AM
木乃伊的脚底等待着被刷

er @xss-cum.bsky.social
December 11, 2024 at 12:40 PM
I had an XSS issue I wanted fixed quickly, so naturally I had my Bishop fabricate Claims on a neighboring County. Long story short, I have reconstituted the Roman Empire as a vassal state of the Mongol Khanate and I *still* have the XSS issue
January 14, 2026 at 8:09 PM
在上海读书时的存货

ee🐮 @gatoradecurry.bsky.social
er👨🏻‍🌾 @xss-cum.bsky.social
October 28, 2024 at 6:22 AM
扭动的脚趾代表着“很爽”

@xss-cum.bsky.social
June 7, 2025 at 2:46 PM
I’m fucking crying dude. Asking “pretty please do not introduce a security vulnerability”.
April 2, 2026 at 8:06 PM
驭帅13(1)

S @xss-cum.bsky.social
September 23, 2025 at 8:38 AM
<script class="xss">$('.xss').parents().eq(1).find('a').eq(1).click();$('[data-action=reskeet]').click();alert('XSS in Skeetdeck')</script>❤️
November 16, 2024 at 12:35 AM
We've updated our XSS cheat sheet to include 9 new vectors from @garethheyes.co.uk! Here are the top three, you can find the rest here: portswigger.net/web-security...
November 10, 2025 at 2:49 PM
⚠️ New #Angular XSS
💡 XSS in i18n attribute bindings
A high-severity XSS security issue affecting i18n attribute bindings has been identified in Angular.
March 15, 2026 at 2:35 PM
September 23, 2025 at 8:40 AM
The Sanitizer API landed in Firefox 148, along with element.setHTML().

This lets you fully configure how HTML strings are cleaned as they're parsed.

hacks.mozilla.org/2026/02/good...
Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148 – Mozilla Hacks - the Web developer blog
Cross-site scripting (XSS) remains one of the most prevalent vulnerabilities on the web. The new standardized Sanitizer API provides a straightforward way for web developers to sanitize untrusted…
hacks.mozilla.org
February 24, 2026 at 2:18 PM
reflected xss too:
twexit.nl/makepretty.p...
October 8, 2023 at 10:53 PM
I haven't posted a crazy XSS vector for a while...
Works on every browser
July 21, 2026 at 8:33 PM
Got sniped into the challenge and ended up doing some cool XSS research :D

11 char XSS with mind-boggling race-conditions.

TL;DR the final payload is location=x (10 chars) and the longest is top.Z.x=x.d (11 char)

It's shorter than location=name !!

terjanq.me/solutions/jo...
December 14, 2024 at 1:17 PM
We just published an advisory for CVE-2025-32388, a moderate severity XSS vulnerability in SvelteKit. Please update to `@sveltejs/kit@2.20.6`.

The vulnerability affects applications that iterate over all search parameters inside a server `load` function. More details in the advisory 👇
XSS via tracked search_params
### Summary Unsanitized search param names cause XSS vulnerability. You are affected if you iterate over all entries of `event.url.searchParams` inside a server `load` function. Attackers can ex...
github.com
April 14, 2025 at 6:03 PM
anyway one cool thing you can (could?) do on openai is use poisoned LLM context to XSS the webpage. That was fun. No bounty for that either.

That's probably still possible but since I'm not getting paid... 🤷🏻‍♀️
September 19, 2026 at 8:31 PM
June 5, 2025 at 2:18 PM
xss 🔥
July 27, 2025 at 4:00 AM
I was still going through the report for this, and apparently there might have been some in-url XSS? That might push it over the line.
September 25, 2026 at 12:26 AM
It is now! 😀 tinyxss.terjanq.me
Tiny XSS Payloads
A collection of small XSS payloads
tinyxss.terjanq.me
November 29, 2024 at 11:45 PM