Free XSS Labs — Practice Cross-Site Scripting

Hands-on cross-site scripting labs running entirely in your browser. Cover every major XSS variant attackers use in real bug bounties — reflected, stored, DOM-based, attribute-context, and sanitiser-bypass cases. No VM setup, no signup required to play, free forever.

Cross-site scripting remains the most-reported web vulnerability in bug bounty programs year after year. These labs walk you through the exact patterns you'll encounter on real targets — from a simple search-box reflection to attribute-quote-breakouts and SVG-based sanitiser bypasses. Each lab tracks your time-to-solve and rewards XP on completion. Start with the beginner labs to learn the fundamentals, then move to intermediate variants that mirror what bug bounty hunters actually find in production today.

5 Labs in this category
Free No subscription