
PayPal merchant directory reflected XSS
A duplicated q parameter in PayPal’s merchant directory let an injected payload break out of script context, producing a reflected XSS that PayPal patched within days.

A duplicated q parameter in PayPal’s merchant directory let an injected payload break out of script context, producing a reflected XSS that PayPal patched within days.

A Firefox-only reflected XSS on wwwb.search.billmelater.com, achieved by closing out of a style attribute and injecting a fresh script element, which the vendor classified as out of scope.