Stefano Di Paola edited this page Jul 14, 2016 · 3 revisions


The DOMXSS Wiki is a Knowledge Base for defining sources of attacker controlled inputs and sinks which potentially could introduce DOM Based XSS issues. DOMXSS first being thoroughly documented in a paper by Amit Klein in 2005 has risen in relevance over the last years - nevertheless still lacking a central place for collecting information and knowledge about it.

The project aims top be this very place and to identify sources and sinks methods exposed by public, widely used javascript frameworks. The project is a work in progress and will be extended over time. Contributions are welcome.

Please use the sidebar menu to navigate contents.

This project is mainly maintained by Stefano Di Paola.

Warm thanks to the following active contributors:

  • Mario Heiderich
  • Frederik Braun
  • Giuseppe Trotta

Feel free to collaborate!

This project is sponsored by:

You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session.
Press h to open a hovercard with more details.