XSS
XSS Lab
craft · inject · fire
← All Tools
Injection Context
Your Payload
▶ Test in iframe
Clear
Copy
Test through DOMPurify
Config
ALLOWED_TAGS
ALLOWED_ATTR
Options
FORCE_BODY
ALLOW_DATA_ATTR
ALLOW_UNKNOWN_PROTOCOLS
Sanitized output
Quick Payloads
— click to use
example.com — click ▶ Test to load