XSSes are everywhere. They've been the most common vulnerability class for years. But while popping an alert may seem simple, there's much more to cross-site scripting than meets the eye. What payloads actually work in production? Where are hunters finding XSS in modern applications? Can you submit reports without CSP bypasses, or is that now mandatory? What parameters should be in your wordlists? To answer these questions, I extracted hundreds of XSS reports from the internet and analyzed 174 of them to understand how people actually make money with this bug class. This study reveals the most common XSS types, root causes, and locations where they're found.
You'll discover what payloads and filter bypasses work in practice, how often blind XSS appears, and how frequently CSP bypasses are required. Includes a wordlist of vulnerable parameters and the complete database of all reports analyzed.
XSS – case study of 174 reports
