A small collection of labs demonstrating unexpected vulnerabilities discovered in real-world bug bounty targets.
JQuery text function leading to XSS
URL parsing to trigger XSS
Moment JS feature that can be used to trigger XSS