<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Xss — PoC Archive</title><link>https://poc.intelseclab.com/tags/xss/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/xss/index.xml" rel="self" type="application/rss+xml"/><item><title>WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell")</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</guid><description>High severity (CVSS 8.9) — web · CVE-2026-64638. Status: Patched. Affects: WordPress Core, wp-login.php failed-login error message, KSES sanitizer vs PHP strip_tags(). Tags: wordpress, wordpress-core, pre-auth, xss, reflected-xss, xss2shell, rce, parser-differential, dom-clobbering, some, jsonp, rest-api, application-password, plugin-upload, CWE-79, CWE-94, cms.</description><category>web</category><category>High</category><category>wordpress</category><category>wordpress-core</category><category>pre-auth</category><category>xss</category><category>reflected-xss</category><category>xss2shell</category><category>rce</category><category>parser-differential</category><category>dom-clobbering</category><category>some</category><category>jsonp</category><category>rest-api</category><category>application-password</category><category>plugin-upload</category><category>CWE-79</category><category>CWE-94</category><category>cms</category></item><item><title>WordPress "List Site Contributors" Plugin Reflected XSS Scanner (CVE-2026-0594)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0594-listsitecontributors-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0594-listsitecontributors-xss/</guid><description>Medium severity — web · CVE-2026-0594. Status: PoC. Affects: "List Site Contributors" WordPress plugin. Tags: wordpress, xss, reflected-xss, wp-json, rest-api, plugin-vulnerability, golang, scanner.</description><category>web</category><category>Medium</category><category>wordpress</category><category>xss</category><category>reflected-xss</category><category>wp-json</category><category>rest-api</category><category>plugin-vulnerability</category><category>golang</category><category>scanner</category></item><item><title>OWASP CoreRuleSet Multipart Charset WAF Bypass (CVE-2026-21876)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21876-crs-waf-multipart-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21876-crs-waf-multipart-bypass/</guid><description>Critical severity — web · CVE-2026-21876. Status: PoC. Tags: waf-bypass, owasp-crs, modsecurity, multipart-form-data, charset-smuggling, xss, docker-lab.</description><category>web</category><category>Critical</category><category>waf-bypass</category><category>owasp-crs</category><category>modsecurity</category><category>multipart-form-data</category><category>charset-smuggling</category><category>xss</category><category>docker-lab</category></item><item><title>oRPC OpenAPI Reference Plugin Stored XSS via Unescaped Spec Embedding (CVE-2026-33331)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33331-orpc-openapi-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33331-orpc-openapi-stored-xss/</guid><description>High severity — web · CVE-2026-33331 (GHSA-7f6v-3gx7-27q8). Status: PoC. Affects: middleapi/orpc — OpenAPI documentation reference plugin (packages/openapi/src/plugins/openapi-reference.ts). Tags: xss, stored-xss, orpc, openapi, cwe-79, javascript, nodejs, docs-page.</description><category>web</category><category>High</category><category>xss</category><category>stored-xss</category><category>orpc</category><category>openapi</category><category>cwe-79</category><category>javascript</category><category>nodejs</category><category>docs-page</category></item><item><title>OpenSTAManager Reflected XSS via `righe` Parameter (CVE-2026-24415)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24415-openstamanager-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24415-openstamanager-xss/</guid><description>Medium severity — web · CVE-2026-24415 (GHSA-jfgp-g7x7-j25j). Status: PoC. Affects: OpenSTAManager (devcode-it/openstamanager). Tags: xss, reflected-xss, openstamanager, cwe-79, session-hijacking, php, unauthenticated-payload.</description><category>web</category><category>Medium</category><category>xss</category><category>reflected-xss</category><category>openstamanager</category><category>cwe-79</category><category>session-hijacking</category><category>php</category><category>unauthenticated-payload</category></item><item><title>NextScripts Social Networks Auto-Poster — WordPress Stored XSS (CVE-2026-3228)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3228-nextscripts-wp-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3228-nextscripts-wp-stored-xss/</guid><description>Medium severity (CVSS 6.4) — web · CVE-2026-3228. Status: PoC. Affects: NextScripts: Social Networks Auto-Poster (WordPress plugin). Tags: wordpress, xss, stored-xss, plugin, contributor-privilege, shortcode, session-hijacking.</description><category>web</category><category>Medium</category><category>wordpress</category><category>xss</category><category>stored-xss</category><category>plugin</category><category>contributor-privilege</category><category>shortcode</category><category>session-hijacking</category></item><item><title>Gravity Forms Unauthenticated Reflected XSS via `gform_get_config` `form_ids` Parameter (CVE-2026-4406)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4406-gravity-forms-reflected-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4406-gravity-forms-reflected-xss/</guid><description>Medium severity (CVSS 6.1) — web · CVE-2026-4406. Status: PoC. Affects: Gravity Forms (WordPress plugin) by Rocketgenius, Inc.. Tags: wordpress, gravity-forms, xss, reflected-xss, admin-ajax, unauthenticated, cwe-79.</description><category>web</category><category>Medium</category><category>wordpress</category><category>gravity-forms</category><category>xss</category><category>reflected-xss</category><category>admin-ajax</category><category>unauthenticated</category><category>cwe-79</category></item><item><title>BentoPDF Stored XSS to File Exfiltration (CVE-2026-41653)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-41653-bentopdf-stored-xss-exfil/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-41653-bentopdf-stored-xss-exfil/</guid><description>Critical severity — web · CVE-2026-41653. Status: PoC. Affects: BentoPDF (self-hosted browser-side PDF toolbox). Tags: xss, stored-xss, file-exfiltration, client-side, service-worker, wasm-hijack, pdf-toolbox, markdown-injection.</description><category>web</category><category>Critical</category><category>xss</category><category>stored-xss</category><category>file-exfiltration</category><category>client-side</category><category>service-worker</category><category>wasm-hijack</category><category>pdf-toolbox</category><category>markdown-injection</category></item><item><title>FirefUXSS: Universal XSS in Firefox Focus for iOS via Redirect-Scheme Validation Race Condition</title><link>https://poc.intelseclab.com/pocs/web/2026-06-08_firefox-focus-ios-uxss-redirect-scheme-race-condition/</link><pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-06-08_firefox-focus-ios-uxss-redirect-scheme-race-condition/</guid><description>Critical severity (CVSS 9.3) — web. Status: Unpatched. Affects: Firefox Focus for iOS. Tags: UXSS, XSS, race-condition, TOCTOU, redirect-validation, javascript-scheme, iOS, Firefox Focus.</description><category>web</category><category>Critical</category><category>UXSS</category><category>XSS</category><category>race-condition</category><category>TOCTOU</category><category>redirect-validation</category><category>javascript-scheme</category><category>iOS</category><category>Firefox Focus</category></item><item><title>Next.js CSP Nonce Cache-Poisoned XSS (CVE-2026-44581)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-csp-nonce-cache-poisoned-xss/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-csp-nonce-cache-poisoned-xss/</guid><description>Medium severity (CVSS 4.7) — web · CVE-2026-44581. Status: Weaponized. Affects: Next.js App Router applications using CSP nonces. Tags: XSS, cache-poisoning, CSP-nonce, Next.js, App-Router, unauthenticated.</description><category>web</category><category>Medium</category><category>XSS</category><category>cache-poisoning</category><category>CSP-nonce</category><category>Next.js</category><category>App-Router</category><category>unauthenticated</category></item><item><title>Next.js beforeInteractive Script XSS (CVE-2026-44580)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-beforeinteractive-script-xss/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-beforeinteractive-script-xss/</guid><description>Medium severity (CVSS 6.1) — web · CVE-2026-44580. Status: Weaponized. Affects: Next.js applications using next/script with strategy="beforeInteractive". Tags: XSS, next/script, beforeInteractive, Next.js, App-Router, unauthenticated.</description><category>web</category><category>Medium</category><category>XSS</category><category>next/script</category><category>beforeInteractive</category><category>Next.js</category><category>App-Router</category><category>unauthenticated</category></item></channel></rss>