Post cover image

August 5, 2026

Bypassing a “Safe” Input Field: Reflected XSS via Unescaped HTML Attribute Injection

How a form parameter that never touches <script> tags can still execute arbitrary JavaScript — and why blacklisting < and > isn't enough.

By Reza

5 min read