XSS Practice Pack

A single-topic practice pack for CWAP Module 03: Cross-Site Scripting. Each mini-lab below is isolated and drills XSS and nothing else.

Naked labs

Minimal UI, one or two features, exactly one exploitable sink each. No hunting - the bug is right where you look. Learn one context at a time.

Methodology labs

Realistic apps with many inputs where most are correctly encoded and only ONE input in ONE context is exploitable. Probe systematically, find the real sink, prove it.

There are no flag{...} values here. Proof of execution is self-contained: any payload that runs should call /m03-p/api/solve/<slug>. Track your session on Progress.