Cross-Site Scripting https://wiki.owasp.org/index.php/Cross-site_Scripting_(XSS)
References
Hacker101 - XSS Tutorial
Acunetix - Cross-site Scripting (XSS) Attackl
A timing attack with CSS selectors and Javascript
Examples
[2021] - XSS on forums.oculusvr.com leads to Oculus and Facebook account takeovers
[2020] - [gitlab] - Stored XSS on PyPi simple API endpoint
[2020] - [gitlab] Stored XSS in markdown when redacting references
[2020] - Self XSS in Shopify
[2020] - Stored XSS in collabora via user name
[2020] - $25K Instagram Almost XSS Filter Link — Facebook Bug Bounty
[2020] - Stored XSS on upload files leads to steal cookie
[2020] - Reflected XSS in https://blocked.myndr.net
[2019] - Potential unprivileged Stored XSS through wp_targeted_link_rel
[2019] - The Bug That Exposed Your PayPal Password
[2019] - Reflected XSS at https://pay.gold.razer.com escalated to account takeover
[2019] - XSS in GMail’s AMP4Email via DOM Clobbering
[2019] - Stored XSS vulnerability in comments on *.wordpress.com
[2019] - Wordpress Cross-Site Scripting Vulnerability Notification II
[2019] - XSS in Shopify while logging using Google
[2019] - Stored XSS in Wiki pages
[2019] - Stored XSS on https://core.trac.wordpress.org
[2019] - Zomato - Self-Stored XSS - Chained with login/logout CSRF
[2019] - From Parameter Pollution to XSS
[2018] - Stored XSS on Snapchat
[2018] - Stored XSS, and SSRF in Google using the Dataset Publishing Language
[2018] - Blind XSS in one of the Admin Dashboard
[2018] - How I found a stored XSS on thousands of webshops
[2018] - Reflected XSS on https://www.zomato.com
[2018] - Reflected XSS on