References https://www.cloudflare.com/zh-cn/learning/security/threats/cross-site-scripting/ https://info.support.huawei.com/info-finder/encyclopedia/zh/%E8%B7%A8%E7%AB%99%E8%84%9A%E6%9C%AC%E5%87%BB%E6%96%97.html https://blog.csdn.net/2301_77091612/article/details/147613266 https://pdf.hanspub.org/CSA20210100000_49066057.pdf https://www.reddit.com/r/bugbounty/comments/1ifyid9/how_to_exploit_reflected_xss_via_cookie_value/?tl=zh-hans https://edu.51cto.com/article/note/24481.html https://vulwiki.readthedocs.io/zh_CN/latest/web/xss/ https://zhuanlan.zhihu.com/p/397940947 https://cloud.tencent.com/developer/article/2519250 https://www.cnblogs.com/Hekeats-L/p/16927573.html
Related VulnerabilitiesPoCCVE-2026-11801: WPAdverts <= 2.3.2 - Information DisclosurePoCCVE-2026-10768: Drupal LocalGov Workflows < 1.6.0 - Information DisclosurePoCCVE-2026-27796: Homarr < 1.54.0 - Information DisclosurePoCCVE-2026-1980: WPBookit <= 1.0.8 - Unauthenticated Customer Information DisclosurePoCCVE-2026-8386: WP Go Maps < 10.0.10 - Unauthenticated Marker Information DisclosurePoCCVE-2026-22778: vLLM 0.8.3 - 0.14.0 - Information DisclosurePoCCVE-2026-8383: LearnPress < 4.3.7 - Information DisclosurePoCweaver-getemdslist-disclosure: Weaver E-cology getEmDsList Sensitive Information DisclosurePoCCVE-2026-54236: vLLM <= 0.23.0 - Anthropic Router Heap Address Information LeakPoCCVE-2022-44727: PrestaShop lgcookieslaw - SQL InjectionPoCCVE-2024-6569: Campaign Monitor for WordPress - Information DisclosurePoCCVE-2026-27833: Piwigo < 16.3.0 - Unauthenticated Information Disclosure via History APIPoCCVE-2026-40151: PraisonAI AgentOS - Information Disclosure