-

Reflected DOM-based XSS on DomaiNesia
In this article, I’ll walk you through how I discovered a Reflected DOM-based Cross-site Scripting (XSS) vulnerability on…
-

Exploiting XSS via Markdown on Xiaomi
Markdown is a popular text-to-HTML conversion tool, commonly used in forums and web platforms to create web content.…
-

N45HT Vulnerability Disclosure Program
No technology is perfect, and N45HT believes that working with skilled security researchers across the globe is crucial…
-

Reflected XSS on Microsoft
During my recent bug bounty hunting, I started by gathering information on the Microsoft domain using a simple…
-

XSSR: An automatic XSS scanner
Is an automatic Cross-site Scripting scanner application with Website, Chrome Extensions, and Windows Desktop platforms. Get in touch:
-

$300 Bounty for Exploiting DOM-based XSS
While analyzing XING’s event management platform, I identified a reflected XSS vulnerability in the way event IDs are…
-

Reflected XSS on AT&T
While performing a Google Dork search for potential vulnerabilities, I used the following query to target AT&T’s website:…
-

API: Subdomain Enumeration
Subdomain Enumeration is the process of finding sub-domains of a domain, this is an important phase in a…
Recent Posts
- The CSS Backdoor Nobody Talks AboutWebmail clients like Gmail, Outlook, and Fastmail sanitize untrusted HTML/CSS… Read more: The CSS Backdoor Nobody Talks About
- Critical Analysis of CVE-2026-50522: Microsoft SharePoint Remote Code Execution VulnerabilityMicrosoft SharePoint is one of the most widely used enterprise… Read more: Critical Analysis of CVE-2026-50522: Microsoft SharePoint Remote Code Execution Vulnerability
- We’re Hiring: Python Cybersecurity ExpertHiring Status: Closed Applications for this position are no longer… Read more: We’re Hiring: Python Cybersecurity Expert
- XSSR Pro is Now Available for FreeWe’re excited to announce that XSSR Pro is now available… Read more: XSSR Pro is Now Available for Free
- Drupal CVE-2026-9082 CheckerWe recently created a small Python tool to detect CVE-2026-9082,… Read more: Drupal CVE-2026-9082 Checker
Social Media
Advertisement
Tags
API Bug Bounty Capture The Flag Command Injection Cross-site Scripting CSS CTF CVE-2026-9082 CVE-2026-50522 Drupal ExifTool HTML Information Disclosure JavaScript Markdown Microsoft SharePoint Open Redirection PHP SQL Injection VDP WAF Web Application Firewall XSS XSSR XSSRush




