1. How to Find XSS: Techniques Security Researchers Use in Real Environments research | 2026-04-01 16:00 | hackerone.com | original ↗ | #bug-bounty | #pentesting | #web-security
2. Web Application Black-Box Testing blog | 2023-07-06 14:07 | yeswehack.com | original ↗ | #bug-bounty | #pentesting | #fuzzing
3. Exploring JavaScript's exploits: A deep dive into XSS vulnerabilities research | 2022-12-08 08:25 | yeswehack.com | original ↗ | #bug-bounty | #web-security | #xss
4. Our favourite community contributions to the XSS cheat sheet research | 2022-10-20 08:28 | portswigger.net | original ↗ | #xss | #community | #payloads
5. Web application firewall bypass blog | 2022-10-11 13:55 | yeswehack.com | original ↗ | #bug-bounty | #pentesting | #web-security
6. Documenting the impossible: Unexploitable XSS labs research | 2020-06-04 09:31 | portswigger.net | original ↗ | #web-security | #xss | #payloads
7. Adapting AngularJS payloads to exploit real world applications research | 2019-06-14 12:12 | portswigger.net | original ↗ | #xss | #template-injection | #payloads
8. Sample Burp Suite extension: Intruder payloads blog | 2012-12-21 15:29 | portswigger.net | original ↗ | #burp-suite | #fuzzing | #extensions
9. Intruder botox blog | 2010-03-22 15:33 | portswigger.net | original ↗ | #burp-suite | #fuzzing | #portswigger