⤷ Title: Lab: Reflected XSS into HTML context with nothing encoded
════════════════════════
𐀪 Author: jaejun835
════════════════════════
ⴵ Time: Thu, 26 Feb 2026 05:31:20 GMT
════════════════════════
⌗ Tags: #csp #html #burpsuite #xs #portswigger
════════════════════════
𐀪 Author: jaejun835
════════════════════════
ⴵ Time: Thu, 26 Feb 2026 05:31:20 GMT
════════════════════════
⌗ Tags: #csp #html #burpsuite #xs #portswigger
Medium
Lab: Reflected XSS into HTML context with nothing encoded
[Problem]
⤷ Title: Forcing an AI App to generate Payloads to Cause HTML Injection
════════════════════════
𐀪 Author: Rahul Singh Chauhan
════════════════════════
ⴵ Time: Wed, 04 Mar 2026 01:11:07 GMT
════════════════════════
⌗ Tags: #html_injection #bug_bounty #cybersecurity #ai #bug_bounty_reports
════════════════════════
𐀪 Author: Rahul Singh Chauhan
════════════════════════
ⴵ Time: Wed, 04 Mar 2026 01:11:07 GMT
════════════════════════
⌗ Tags: #html_injection #bug_bounty #cybersecurity #ai #bug_bounty_reports
Medium
Forcing an AI App to generate Payloads to Cause HTML Injection
Hi everyone, in this article, I’ll walk through a recent penetration test I conducted against a custom-built AI chatbot. As usual, we’ll…
⤷ Title: ️♂️ A Fun HTML Injection Story — When a “File Name” Became My Entry Point
════════════════════════
𐀪 Author: Diwas mundra
════════════════════════
ⴵ Time: Wed, 18 Mar 2026 21:42:18 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #sql_injection #vulnerability #html_injection
════════════════════════
𐀪 Author: Diwas mundra
════════════════════════
ⴵ Time: Wed, 18 Mar 2026 21:42:18 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #sql_injection #vulnerability #html_injection
Medium
🕵️♂️ A Fun HTML Injection Story — When a “File Name” Became My Entry Point
Sometimes, vulnerabilities don’t scream… They just quietly sit inside something as innocent as a file name field 😄
⤷ Title: Invisible Ink: Critical 9.6 CVSS jsPDF Flaw Turns Generated Documents into XSS Traps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 13:30:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_31938 #cybersecurity #HTML Injection #infosec #JavaScript Security #jsPDF #Vulnerability #web development #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 13:30:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_31938 #cybersecurity #HTML Injection #infosec #JavaScript Security #jsPDF #Vulnerability #web development #XSS
Daily CyberSecurity
Invisible Ink: Critical 9.6 CVSS jsPDF Flaw Turns Generated Documents into XSS Traps
A critical 9.6 CVSS vulnerability in jsPDF (CVE-2026-31938) allows attackers to inject malicious scripts via XSS. Update to version 4.2.1 immediately.
⤷ Title: HTML Injection Bug Bounty: How I Found a Persistent Vulnerability on a Government of India Portal
════════════════════════
𐀪 Author: Vanshrathore
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 18:22:08 GMT
════════════════════════
⌗ Tags: #bug_bounty #html_injection #pentesting #money #bug_hunting
════════════════════════
𐀪 Author: Vanshrathore
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 18:22:08 GMT
════════════════════════
⌗ Tags: #bug_bounty #html_injection #pentesting #money #bug_hunting
Medium
HTML Injection Bug Bounty: How I Found a Persistent Vulnerability on a Government of India Portal
LinkedIn:- https://www.linkedin.com/in/vansh-rathore-cybersecurity?utm_source=share_via&utm_content=profile&utm_medium=member_android
⤷ Title: From P4 to Critical: How I Weaponized target.com’s Email Infrastructure
════════════════════════
𐀪 Author: Vanshrathore
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 15:18:58 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #html_injection #bug_hunting #money
════════════════════════
𐀪 Author: Vanshrathore
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 15:18:58 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #html_injection #bug_hunting #money
Medium
🔥From P4 to Critical: How I Weaponized target.com’s Email Infrastructure
LinkedIn:- https://www.linkedin.com/in/vansh-rathore-cybersecurity?utm_source=share_via&utm_content=profile&utm_medium=member_android
⤷ Title: How A Simple Bug That Refused to Die, Paid Twice.
════════════════════════
𐀪 Author: kjulius
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 03:03:44 GMT
════════════════════════
⌗ Tags: #injection #ui_interaction #html #bug_bounty #inconsistencies
════════════════════════
𐀪 Author: kjulius
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 03:03:44 GMT
════════════════════════
⌗ Tags: #injection #ui_interaction #html #bug_bounty #inconsistencies
Medium
How A Simple Bug That Refused to Die, Paid Twice. 💰
⚠️ Disclaimer
⤷ Title: How A Simple Bug That Refused to Die, Paid Twice.
════════════════════════
𐀪 Author: kjulius
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 03:03:42 GMT
════════════════════════
⌗ Tags: #injection #ui_interaction #html #bug_bounty #inconsistencies
════════════════════════
𐀪 Author: kjulius
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 03:03:42 GMT
════════════════════════
⌗ Tags: #injection #ui_interaction #html #bug_bounty #inconsistencies
Medium
How A Simple Bug That Refused to Die, Paid Twice. 💰
⚠️ Disclaimer
⤷ Title: bWAPP: HTML Injection — Reflected (GET) Challenge (Low & Medium Security)
════════════════════════
𐀪 Author: Kamal S
════════════════════════
ⴵ Time: Sat, 09 May 2026 12:04:24 GMT
════════════════════════
⌗ Tags: #injection #owasp #html_injection #bwapp #bug_bounty
════════════════════════
𐀪 Author: Kamal S
════════════════════════
ⴵ Time: Sat, 09 May 2026 12:04:24 GMT
════════════════════════
⌗ Tags: #injection #owasp #html_injection #bwapp #bug_bounty
Medium
bWAPP: HTML Injection — Reflected (GET) Challenge (Low & Medium Security)
HTML Injection is one of the most fundamental web application vulnerabilities and often serves as a stepping stone to more advanced attacks…
⤷ Title: HTML Should Have Embedded Markdown 30 Years Ago
════════════════════════
𐀪 Author: Outermostkt
════════════════════════
ⴵ Time: Sun, 17 May 2026 02:08:54 GMT
════════════════════════
⌗ Tags: #thariq #ai #xs #html #markdown
════════════════════════
𐀪 Author: Outermostkt
════════════════════════
ⴵ Time: Sun, 17 May 2026 02:08:54 GMT
════════════════════════
⌗ Tags: #thariq #ai #xs #html #markdown
Medium
HTML Should Have Embedded Markdown 30 Years Ago
As you may know, there’s been a lot of buzz in the AI community lately about shifting back from Markdown to HTML. For instance, in articles…
⤷ Title: The Sleeper Agent Bug: How One HTML Payload Lay Hidden for Months to Attack My Inbox ⏳
════════════════════════
𐀪 Author: LordofHeaven
════════════════════════
ⴵ Time: Tue, 19 May 2026 09:00:53 GMT
════════════════════════
⌗ Tags: #html_injection #web_security #infosec #coffinxp #bug_bounty
════════════════════════
𐀪 Author: LordofHeaven
════════════════════════
ⴵ Time: Tue, 19 May 2026 09:00:53 GMT
════════════════════════
⌗ Tags: #html_injection #web_security #infosec #coffinxp #bug_bounty
Medium
The Sleeper Agent Bug: How One HTML Payload Lay Hidden for Months to Attack My Inbox ⏳
The Sleeper Agent Bug: How One HTML Payload Lay Hidden for Months to Attack My Inbox ⏳ A short recon story about a delayed HTML injection, a surprising phishing vector, and why every output channel …
⤷ Title: Living Off the HTA Land: How Hackers Weaponize a 1999 Windows Utility for Silent Malware Delivery
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 07:04:27 +0000
════════════════════════
⌗ Tags: #Malware #Amatera Info Harvester #ClickFix Social Engineering LummaStealer #ClipBanker Crypto Stealer #CountLoader Staging Framework #Emmenhtal Loader #HTML Application HTA Payload #Living off the Land Binaries #MSHTA Weaponization Malware Delivery #mshta.exe Windows Binary #PurpleFox Rootkit Lineage
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 07:04:27 +0000
════════════════════════
⌗ Tags: #Malware #Amatera Info Harvester #ClickFix Social Engineering LummaStealer #ClipBanker Crypto Stealer #CountLoader Staging Framework #Emmenhtal Loader #HTML Application HTA Payload #Living off the Land Binaries #MSHTA Weaponization Malware Delivery #mshta.exe Windows Binary #PurpleFox Rootkit Lineage
Penetration Testing Tools
Living Off the HTA Land: How Hackers Weaponize a 1999 Windows Utility for Silent Malware Delivery
Threat actors are increasingly weaponizing MSHTA, a legacy Windows utility, as a highly efficient conduit to execute malicious
⤷ Title: HTML Injection in Outbound Emails: An Overlooked Security Risk
════════════════════════
𐀪 Author: vibhuti bhatt
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 12:26:37 GMT
════════════════════════
⌗ Tags: #html_injection #vulnerability #application_security #pentesting #injection_in_email
════════════════════════
𐀪 Author: vibhuti bhatt
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 12:26:37 GMT
════════════════════════
⌗ Tags: #html_injection #vulnerability #application_security #pentesting #injection_in_email
Medium
HTML Injection in Outbound Emails: An Overlooked Security Risk
Introduction
⤷ Title: Telegram Bots Receive Rich HTML and Markdown Formatting Options
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 08:44:45 +0000
════════════════════════
⌗ Tags: #Technology #bot development #HTML formatting #Markdown #Rich Text #Telegram Bots
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 08:44:45 +0000
════════════════════════
⌗ Tags: #Technology #bot development #HTML formatting #Markdown #Rich Text #Telegram Bots
Daily CyberSecurity
Telegram Bots Receive Rich HTML and Markdown Formatting Options
Discover the latest Telegram bot formatting options. Learn how to use rich HTML and Markdown to create engaging, sophisticated messages with advanced styles.
⤷ Title: I Turned a “What’s Your Name?” Field Into a Malicious Link — My First HTML Injection
════════════════════════
𐀪 Author: Prashant Raj
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 10:46:00 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #bug_hunting #html_injection #technology
════════════════════════
𐀪 Author: Prashant Raj
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 10:46:00 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #bug_hunting #html_injection #technology
Medium
I Turned a “What’s Your Name?” Field Into a Malicious Link — My First HTML Injection
TryHackMe — How Websites Work
⤷ Title: I Found a Bug That Looks Harmless But Can Still Get You Paid
════════════════════════
𐀪 Author: Yamini Yadav_369
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 00:03:53 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #html #medium #bug_bounty
════════════════════════
𐀪 Author: Yamini Yadav_369
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 00:03:53 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #html #medium #bug_bounty
Medium
I Found a Bug That Looks Harmless But Can Still Get You Paid
Here is everything I know about HTML Injection, how I test for it, how people bypass filters, and what it actually scores on CVSS
⤷ Title: bWAPP HTML Injection — Reflected (URL) and Stored (Blog)
════════════════════════
𐀪 Author: Kamal S
════════════════════════
ⴵ Time: Sun, 21 Jun 2026 14:03:38 GMT
════════════════════════
⌗ Tags: #injection #html_injection #owasp #bug_bounty #bwapp
════════════════════════
𐀪 Author: Kamal S
════════════════════════
ⴵ Time: Sun, 21 Jun 2026 14:03:38 GMT
════════════════════════
⌗ Tags: #injection #html_injection #owasp #bug_bounty #bwapp
Medium
bWAPP HTML Injection — Reflected (URL) and Stored (Blog)
Web applications heavily rely on user input, but improper handling of this input often introduces security vulnerabilities. One such…
⤷ Title: CSRF: When Your Browser Snitches Behind Your Back
════════════════════════
𐀪 Author: Ziyad
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 01:34:55 GMT
════════════════════════
⌗ Tags: #web_development #html #csrf #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Ziyad
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 01:34:55 GMT
════════════════════════
⌗ Tags: #web_development #html #csrf #cybersecurity #penetration_testing
Medium
CSRF: When Your Browser Snitches Behind Your Back
What are CSRFs ?
⤷ Title: From a “Self-XSS” to a Convincing UI Spoof: A Bug Bounty Story That Ended as a Duplicate.
════════════════════════
𐀪 Author: kjulius
════════════════════════
ⴵ Time: Fri, 26 Jun 2026 19:47:30 GMT
════════════════════════
⌗ Tags: #phishing #html #reflected_xss #self_xss #bug_bounty
════════════════════════
𐀪 Author: kjulius
════════════════════════
ⴵ Time: Fri, 26 Jun 2026 19:47:30 GMT
════════════════════════
⌗ Tags: #phishing #html #reflected_xss #self_xss #bug_bounty
Medium
From a “Self-XSS” to a Convincing UI Spoof: A Bug Bounty Story That Ended as a Duplicate.
There’s a special kind of pain in bug bounty. Not getting an Out of Scope. Not getting an informative.
⤷ Title: GitLab Patch Release Fixes Eight Flaws, Including a High-Severity XSS Bug (CVE-2026-6896)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 02:15:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_13320 #CVE_2026_6896 #DevSecOps #GitLab EE #GitLab patch release #HTML Injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 02:15:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_13320 #CVE_2026_6896 #DevSecOps #GitLab EE #GitLab patch release #HTML Injection
Daily CyberSecurity
GitLab Patch Release Fixes Eight Flaws, Including a High-Severity XSS Bug (CVE-2026-6896)
TL;DR This GitLab patch release, shipped on July 8, 2026, covers versions 19.1.2, 19.0.4, and 18.11.7. The update fixes eight security flaws across Community and Enterprise Edition. The most sever…