🛡️ Controlled Vulnerability Practice

XSS Training Lab

Master Cross-Site Scripting by analyzing, auditing, and exploiting 24 realistic fictional web applications across Reflected, Stored, and DOM contexts.

Reflected XSS

User-controlled input is immediately reflected into server responses. Explore tag filtering, attribute injection, keyword blacklists, parentheses-free execution, and multi-step fuzzing.

💾

Stored XSS

Injected scripts persist inside databases, feeds, and configurations. Audit thread comments, nested tag strips, unencoded audit logs, and simulated administrative bot reviews.

🌐

DOM XSS

Vulnerabilities executed entirely in client-side JavaScript. Trace execution flows from location sources, query params, hash fragments, JSON transforms, and state stores to DOM sinks.

Standard Penetration Testing Methodology

VulnXSS teaches you how to think like a professional security consultant. Rather than blind payload guessing, every lab encourages this systematic assessment workflow:

1 Reconnaissance
2 Identify Input Points
3 Determine Context
4 Analyze Filtering
5 Craft Payload
6 Verify Execution