Reading
PentestingHere Academy
23 Sep 2026
What it is
XSS happens whenever content you control ends up running as JavaScript in someone else's browser instead of being treated as plain text. The three labs here cover the three shapes you'll meet in the wild: reflected, stored, and DOM-based.
The labs here
- TrailBlaze conditions reflected XSS: your input comes straight back in the page's HTML, unescaped, in the same response. A payload only needs to fire once, so the target here is an automated bot that visits a link you send it.
- CampusConnect discussion board stored XSS: your input gets saved to the database first, then rendered unescaped for anyone (in this case, a reviewing bot) who later views the page. No link to send, just a comment to post.
- Lumen Realty DOM XSS filter bypass: nothing touches the server at
all. Client-side JavaScript reads part of the URL and writes it into the
page with
innerHTML, after stripping one specific word. Case matters, and stripping happens only once, so there's more than one way around a filter that narrow.