XSS Comprehensive Test Suite - HTML Mode
Authorized security audit - testing sanitization of HTML payloads when Remarkable parser is bypassed.
1. mXSS via Style Tag Stripping
Testing mutation XSS where style tags may be stripped but inner content preserved:
2. Various img Payloads
Testing image tag event handler injection:
3. Link Payloads
Testing javascript: and data: URI schemes in anchors:
link1 link2 link3 hive-scheme4. iframe Payloads
Testing iframe injection vectors:
(Unsupported src)
(Unsupported src)
(Unsupported https://evil.com)
5. Details/Summary Payloads
Testing interactive element event handlers:
x x6. Table Payloads
Testing CSS and attribute injection in tables:
| x |
| x |
7. Source/Picture Payloads
Testing picture/source element injection:
8. SVG/Math Payloads
Testing SVG and MathML injection (should be stripped):
x9. DOM Clobbering
Testing DOM clobbering vectors:
proto10. Embed Token Injection
Testing post-sanitization embed replacement bypass:
~~~ embed:test twitter metadata:PHNjcmlwdD5hbGVydCgndHdpdHRlci14c3MnKTwvc2NyaXB0Pg== ~~~ ~~~ embed:test reddit metadata:fDxzY3JpcHQ+YWxlcnQoJ3JlZGRpdC14c3MnKTwvc2NyaXB0PnxodHRwczovL3JlZGRpdC5jb20vci90ZXN0L2NvbW1lbnRzLzEvcG9zdHx0ZXN0 ~~~This post is part of an authorized security audit. All payloads are for testing sanitization only.