1. DOM Invader and the case of direct eval vs indirect eval blog | 2023-09-25 14:00 | portswigger.net | original ↗ | #portswigger-research | #dom-invader | #dom-xss
2. Bypassing CSP via DOM clobbering research | 2023-06-05 14:00 | portswigger.net | original ↗ | #burp-suite | #web-security | #xss
3. Detecting web message misconfigurations for cross-domain credential theft research | 2022-11-09 14:13 | portswigger.net | original ↗ | #burp-suite | #credential-theft | #dom-invader
4. Widespread prototype pollution gadgets research | 2022-10-28 13:04 | portswigger.net | original ↗ | #web-security | #prototype-pollution | #dom-invader
5. Finding DOM Polyglot XSS in PayPal the Easy Way research | 2022-09-07 09:04 | portswigger.net | original ↗ | #bug-bounty | #dom-invader | #dom-xss
6. Finding client-side prototype pollution with DOM Invader blog | 2022-06-20 12:37 | portswigger.net | original ↗ | #burp-suite | #xss | #client-side-security
7. Introducing DOM Invader: DOM XSS just got a whole lot easier to find blog | 2021-06-30 16:47 | portswigger.net | original ↗ | #burp-suite | #xss | #portswigger