HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors
updated at Nov. 14, 2024, 1:46 p.m.
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
updated at Nov. 16, 2024, 11:22 p.m.