Yet another Expert XSS Lab. Highly suggest reviewing
Reflected XSS protected by very strict CSP, with dangling markup attack | Practitioner
Exploiting cross-site scripting to capture passwords | Practitioner
Exploiting XSS to bypass CSRF defenses | Practitioner
Exploiting cross-site scripting to steal cookies | Practitioner
Reflected XSS into a template literal with angle brackets, single, double quotes, backslash and backticks Unicode-escaped | Practitioner
Stored XSS into onclick event with angle brackets and double quotes HTML-encoded and single quotes and backslash escaped | Practitioner
Reflected XSS in a JavaScript URL with some characters blocked | Expert
Reflected XSS into a JavaScript string with angle brackets and double quotes HTML-encoded and single quotes escaped | Practitioner
Reflected XSS into a JavaScript string with single quote and backslash escaped | Practitioner
Reflected XSS in canonical link tag | Practitioner
Very very interesting lab involving canonical tags, highly suggest reviewing (quite long tho)
Stored XSS into anchor href attribute with double quotes HTML-encoded | Apprentice
Reflected XSS into attribute with angle brackets HTML-encoded | Apprentice
Reflected XSS with some SVG markup allowed | Practitioner
Reflected XSS with event handlers and href attributes blocked | Expert
My first Expert lab! Quirk regarding svg
Reflected XSS into HTML context with all tags blocked except custom ones | Practitioner
Interesting lab regarding HTML custom tags. Very fun
Reflected XSS into HTML context with most tags and attributes blocked | Practitioner
Stored DOM XSS | Practitioner
Reflected DOM XSS | Practitioner
DOM XSS in AngularJS expression with angle brackets and double quotes HTML-encoded | Practitioner
Quirk involving AngularJS function filter. Highly suggest reviewing