XSS Cheat Sheet

This 32-page booklet includes 100+ Cross-Site Scripting payloads and techniques with clear directions in several possible scenarios to help you with modern XSS. Sample here.

Table of Contents:

1. Basics
2. Advanced
3. Bypass
4. Exploiting
5. Extra
6. Brutal

Changelog (additions to 2019 edition):

  • More encoding tricks;
  • More alternatives to alert(1);
  • Javascript string obfuscation;
  • More agnostic event handlers;
  • More XSS in specific scenarios;
  • 20+ complex obfuscated payloads;
  • More comprehensive XSS vector scheme.