| 210000-1 |
DOM XSS via inline event handler |
beta |
High |
Tool |
| 210000-2 |
DOM XSS via Element.innerHTML |
beta |
High |
Tool |
| 210000-3 |
DOM XSS via Element.outerHTML |
beta |
High |
Tool |
| 210000-4 |
DOM XSS via insertAdjacentHTML |
beta |
High |
Tool |
| 210000-5 |
DOM XSS via document.write |
beta |
High |
Tool |
| 210000-6 |
DOM XSS via DOM mutations |
beta |
High |
Tool |
| 210001-1 |
Dynamic code execution via eval |
beta |
High |
Tool |
| 210001-2 |
Dynamic code execution via Function constructor |
beta |
High |
Tool |
| 210001-3 |
Dynamic code execution via Function.apply |
beta |
High |
Tool |
| 210002-1 |
Open redirect via window.open |
beta |
Low |
Tool |
| 210002-2 |
Open redirect via Navigation API |
beta |
Low |
Tool |
| 210003-1 |
javascript: URL assigned to href |
beta |
High |
Tool |
| 210003-2 |
javascript: URL navigated via location.href |
beta |
High |
Tool |
| 210003-3 |
javascript: URL assigned to iframe.src |
beta |
High |
Tool |
| 210003-4 |
data: URL assigned to script.src |
beta |
High |
Tool |
| 210003-5 |
data: URL assigned to href |
beta |
High |
Tool |
| 210003-6 |
javascript: URL assigned to src |
beta |
High |
Tool |
| 210003-7 |
data: URL assigned to src |
beta |
High |
Tool |
| 210003-8 |
data: URL navigated via location.href |
beta |
High |
Tool |
| 210003-9 |
javascript: URL navigated via location.assign |
beta |
High |
Tool |
| 210003-10 |
data: URL navigated via location.assign |
beta |
High |
Tool |
| 210003-11 |
javascript: URL navigated via location.replace |
beta |
High |
Tool |
| 210003-12 |
data: URL navigated via location.replace |
beta |
High |
Tool |
| 210003-13 |
javascript: URL opened via window.open |
beta |
High |
Tool |
| 210003-14 |
data: URL opened via window.open |
beta |
High |
Tool |
| 210003-15 |
data: URL assigned to iframe.src |
beta |
High |
Tool |
| 210004-1 |
Route-controlled history.replaceState |
beta |
Medium |
Tool |
| 210004-2 |
Route-controlled Navigation API transition |
beta |
Medium |
Tool |
| 210004-3 |
Route-controlled history.pushState |
beta |
Medium |
Tool |
| 210005-1 |
Form action manipulated by tainted route or body input |
beta |
Medium |
Tool |
| 210005-2 |
formAction manipulated by tainted route or body input |
beta |
Medium |
Tool |
| 210006-1 |
javascript: URL assigned to form action |
beta |
High |
Tool |
| 210006-2 |
javascript: URL assigned to formAction |
beta |
High |
Tool |
| 210006-3 |
data: URL assigned to form action |
beta |
Medium |
Tool |
| 210006-4 |
data: URL assigned to formAction |
beta |
Medium |
Tool |
| 210007-1 |
Response field rendered via innerHTML |
beta |
High |
Tool |
| 210007-2 |
Response field rendered via document.write |
beta |
High |
Tool |
| 210007-3 |
Response field rendered via outerHTML |
beta |
High |
Tool |
| 210007-4 |
Response field rendered via insertAdjacentHTML |
beta |
High |
Tool |
| 210007-5 |
Response field rendered via DOM mutation |
beta |
Medium |
Tool |
| 210007-6 |
Response field parsed via DOMParser |
beta |
Medium |
Tool |
| 210007-7 |
Response field parsed via createContextualFragment |
beta |
Medium |
Tool |
| 210007-8 |
Response field rendered via setHTMLUnsafe |
beta |
High |
Tool |
| 210007-9 |
Response field rendered via ShadowRoot.setHTMLUnsafe |
beta |
High |
Tool |
| 210008-1 |
Prototype pollution influenced fetch() init |
beta |
High |
Tool |
| 210008-2 |
Tainted dangerous key used in prototype write |
beta |
Medium |
Tool |
| 210009-1 |
AngularJS expression executed through Function constructor |
beta |
High |
Tool |
| 210009-2 |
AngularJS $parse expression from form input |
beta |
High |
Tool |
| 210009-3 |
AngularJS $parse expression from cookie |
beta |
High |
Tool |
| 210009-4 |
AngularJS $parse expression from localStorage |
beta |
High |
Tool |
| 210009-5 |
AngularJS $parse expression from postMessage |
beta |
High |
Tool |
| 210010-1 |
postMessage to wildcard origin with tainted payload |
beta |
Medium |
Tool |
| 210010-2 |
postMessage to cross-origin target with tainted payload |
beta |
Medium |
Tool |
| 210011-1 |
Tainted string executed via setTimeout |
beta |
High |
Tool |
| 210011-2 |
Tainted string executed via setInterval |
beta |
High |
Tool |
| 210012-1 |
IFrame navigation via src |
beta |
Medium |
Tool |
| 210012-2 |
IFrame content injection via srcdoc |
beta |
Medium |
Tool |
| 210013-1 |
Exfiltration via fetch URL |
beta |
High |
Tool |
| 210013-2 |
Exfiltration via fetch headers |
beta |
High |
Tool |
| 210013-3 |
Exfiltration via XMLHttpRequest URL |
beta |
High |
Tool |
| 210013-4 |
Exfiltration via XMLHttpRequest body |
beta |
High |
Tool |
| 210013-5 |
Exfiltration via XMLHttpRequest headers |
beta |
High |
Tool |
| 210013-6 |
Exfiltration via navigator.sendBeacon |
beta |
High |
Tool |
| 210013-7 |
Exfiltration via image.src beacon |
beta |
Medium |
Tool |
| 210014-1 |
Tainted URL assigned to element.href |
beta |
Low |
Tool |
| 210014-2 |
Tainted URL assigned to element.src |
beta |
Low |
Tool |
| 210014-3 |
Tainted URL assigned to form action |
beta |
Low |
Tool |
| 210014-4 |
Tainted URL assigned to formAction |
beta |
Low |
Tool |
| 210015-1 |
Client-side redirect via location.href |
beta |
Low |
Tool |
| 210015-2 |
Client-side redirect via location.assign |
beta |
Low |
Tool |
| 210015-3 |
Client-side redirect via location.replace |
beta |
Low |
Tool |
| 210015-4 |
Client-side redirect via history.pushState |
beta |
Low |
Tool |
| 210015-5 |
Client-side route change via history.replaceState |
beta |
Low |
Tool |
| 210016-1 |
DOM XSS via DOMParser.parseFromString |
beta |
Medium |
Tool |
| 210016-2 |
DOM XSS via Range.createContextualFragment |
beta |
High |
Tool |
| 210016-3 |
DOM XSS via Element.setHTMLUnsafe |
beta |
High |
Tool |
| 210016-4 |
DOM XSS via ShadowRoot.setHTMLUnsafe |
beta |
High |
Tool |
| 210017-1 |
DOM XSS via innerHTML (secondary sources) |
beta |
High |
Tool |
| 210017-2 |
DOM XSS via outerHTML (secondary sources) |
beta |
High |
Tool |
| 210017-3 |
DOM XSS via insertAdjacentHTML (secondary sources) |
beta |
High |
Tool |
| 210017-4 |
DOM XSS via document.write (secondary sources) |
beta |
High |
Tool |
| 210017-5 |
DOM XSS via inline handlers (secondary sources) |
beta |
High |
Tool |
| 210017-6 |
DOM XSS via DOM mutation (secondary sources) |
beta |
High |
Tool |
| 210017-7 |
DOM XSS via iframe.srcdoc (secondary sources) |
beta |
High |
Tool |
| 210018-1 |
eval() from storage/referrer taint |
beta |
High |
Tool |
| 210018-2 |
Function() from storage/referrer taint |
beta |
High |
Tool |
| 210018-3 |
Function.apply() from storage/referrer taint |
beta |
High |
Tool |
| 210018-4 |
setTimeout(string) from storage/referrer taint |
beta |
High |
Tool |
| 210018-5 |
setInterval(string) from storage/referrer taint |
beta |
High |
Tool |
| 210019-1 |
location.href redirect from tainted source |
beta |
Medium |
Tool |
| 210019-2 |
location.assign redirect from tainted source |
beta |
Medium |
Tool |
| 210019-3 |
location.replace redirect from tainted source |
beta |
Medium |
Tool |
| 210019-4 |
window.open redirect from tainted source |
beta |
Medium |
Tool |
| 210019-5 |
navigation.navigate redirect from tainted source |
beta |
Medium |
Tool |
| 210019-6 |
Anchor href manipulated from tainted source |
beta |
Medium |
Tool |
| 210019-7 |
Form action manipulated from tainted source |
beta |
Medium |
Tool |
| 220000-8 |
DOM-based XSS (taint flow) |
beta |
High |
Tool |
| 220000-9 |
DOM XSS via innerHTML (Angular) |
beta |
High |
Tool |
| 220001-2 |
DOM-based Cookie Manipulation (taint flow) |
beta |
Medium |
Tool |
| 220002-3 |
DOM-based Open Redirection (taint flow) |
beta |
Medium |
Tool |
| 220003-5 |
DOM-based JavaScript Injection (taint flow) |
beta |
High |
Tool |
| 220004-1 |
Tainted data passed to AngularJS $parse |
beta |
High |
Tool |
| 220004-2 |
Tainted data compiled as AngularJS template |
beta |
High |
Tool |
| 220004-3 |
Dynamic AngularJS $parse expression |
beta |
High |
Tool |
| 220004-4 |
Dynamic AngularJS $compile/$interpolate template |
beta |
High |
Tool |
| 220004-5 |
AngularJS interpolation delimiters in template string |
beta |
High |
Tool |
| 220004-6 |
AngularJS ng-* expression attribute |
beta |
High |
Tool |
| 220005-1 |
Dynamic template compilation |
beta |
High |
Tool |
| 220005-2 |
Template output injected into DOM |
beta |
High |
Tool |
| 220005-4 |
Template injection (taint flow) |
beta |
High |
Tool |
| 220005-5 |
React dangerouslySetInnerHTML taint flow |
beta |
High |
Tool |
| 220005-6 |
Lit unsafeHTML taint flow |
beta |
High |
Tool |
| 220006-5 |
Tainted network destination URL |
beta |
Medium |
Tool |
| 220007-8 |
Tainted worker or script loader URL |
beta |
Medium |
Tool |
| 220008-2 |
Specify postMessage targetOrigin |
beta |
Medium |
Tool |
| 220008-5 |
Origin check uses host fragment only |
beta |
Medium |
Tool |
| 220008-7 |
Message handler without origin validation |
beta |
Medium |
Tool |
| 220008-8 |
Wildcard reply from message handler |
beta |
Medium |
Tool |
| 220008-9 |
Web Message Injection (taint flow) |
beta |
Medium |
Tool |
| 220009-2 |
DOM-based Link Manipulation (taint flow) |
beta |
Medium |
Tool |
| 220010-1 |
Untrusted DOM data into navigation-adjacent sinks |
beta |
Medium |
Tool |
| 220010-2 |
Untrusted DOM data into createHTMLDocument |
beta |
Medium |
Tool |
| 220010-3 |
Untrusted DOM data into UI mutation sinks |
beta |
Medium |
Tool |