Skip to main content
This page aggregates cross-platform resources to practice Cross-Site Scripting (XSS): retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 59 challenges across 3 platforms โ€” 13 HackTheBox ยท 36 PortSwigger ยท 10 TryHackMe. 13 with a Spanish writeup, 21 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwigger โ€” DOM XSS in document.write sink using source location.search (Apprentice) ยท ๐Ÿ‡ฌ๐Ÿ‡ง
  2. PortSwigger โ€” DOM XSS in innerHTML sink using source location.search (Apprentice) ยท ๐Ÿ‡ฌ๐Ÿ‡ง
  3. PortSwigger โ€” DOM XSS in jQuery anchor href attribute sink using location.search source (Apprentice) ยท ๐Ÿ‡ฌ๐Ÿ‡ง ๐Ÿ“น
  4. PortSwigger โ€” DOM XSS in jQuery selector sink using a hashchange event (Apprentice) ยท ๐Ÿ‡ฌ๐Ÿ‡ง
  5. PortSwigger โ€” Exploiting DOM clobbering to enable XSS (Apprentice) ยท ๐Ÿ‡ฌ๐Ÿ‡ง
  6. PortSwigger โ€” Reflected XSS in a JavaScript URL with some characters blocked (Apprentice) ยท ๐Ÿ‡ฌ๐Ÿ‡ง

Curated resources

HTB machines practicing Cross-Site Scripting (XSS) (13)

PortSwigger labs practicing Cross-Site Scripting (XSS) (36)

TryHackMe rooms practicing Cross-Site Scripting (XSS) (10)


โ† Back to the full glossary Last updated: 2026-08-17