Published 11 years 8 months ago • Last updated March 26, 2025 • ⏱️ 3 min read ← Back to articles Mutation XSS was coined by me and Mario Heiderich to describe an XSS vector that is mutated from a safe state into an unsafe unfiltered state. The most common form of mXSS is from incorrect reads of innerHTML. A good example of mXSS was discovered by Mario where the listing element mutated its contents

