By louis.random on Skatehive
XSS Payload Test Suite for Hive Frontends `` ⚠️ FOR AUTHORIZED TESTING ONLY Do not use against systems without explicit written permission. Report ID: AUDIT-20260322 Auditor: louis88 ` Purpose: Post each payload as a Hive blockchain post body to test sanitization across condenser and other Hive frontends. All payloads use alert(1) or alert(document.domain) as a benign proof-of-concept indicator. How to use: Each section contains payloads wrapped in markdown code fences for reference, followed by the raw payload to copy. Test each payload as: A standalone post body Wrapped in ... tags (triggers the raw HTML path in MarkdownViewer) Inside a markdown paragraph mixed with normal text As a comment on an existing post Table of Contents Standard Vectors HTML Tag Event Handlers — Exhaustive SVG Vectors MathML Vectors HTML5 Semantic & Obscure Tags Encoding Bypass Vectors Unicode & Character Tricks CSS-Based Vectors Markdown-Specific Vectors Mutation XSS (mXSS) DOM Clobbering Chains Template & F