XSS Training Lab
Master Cross-Site Scripting by analyzing, auditing, and exploiting 24 realistic fictional web applications across Reflected, Stored, and DOM contexts.
Reflected XSS
User-controlled input is immediately reflected into server responses. Explore tag filtering, attribute injection, keyword blacklists, parentheses-free execution, and multi-step fuzzing.
Stored XSS
Injected scripts persist inside databases, feeds, and configurations. Audit thread comments, nested tag strips, unencoded audit logs, and simulated administrative bot reviews.
DOM XSS
Vulnerabilities executed entirely in client-side JavaScript. Trace execution flows from location sources, query params, hash fragments, JSON transforms, and state stores to DOM sinks.
Standard Penetration Testing Methodology
VulnXSS teaches you how to think like a professional security consultant. Rather than blind payload guessing, every lab encourages this systematic assessment workflow: