#xss
Live, measured metrics for the hashtag #xss from the open social web. Every number carries a named source and the time it was fetched. Nothing is estimated.
Own #xss
This #name is available to claim. It becomes your portal on the open agent web: this very page, a keyword you rank for by an open public stake, and a verifiable identity for AI agents. Nobody else sells a page like this for every #name.
Day-by-day usage
measured · mastodon.online (Mastodon public tags API) · fetched 2026-09-15 11:12 UTC4 uses by 4 unique accounts across the window. Real per-day counts, not estimates. Newest bar is today so far.
Related hashtags
measured · mastodon.online (Mastodon public search API) · fetched 2026-09-15 11:12 UTCLive pulse
measured · mastodon.online (Mastodon tag timeline) · fetched 2026-09-15 11:12 UTCEverything below is measured over the latest 40 public posts (spanning ~929 hours).
Posting hours (UTC) — busiest: 13:00
Languages: English (26) · German (6) · Russian (4) · Polish (2) · Portuguese (1) · Italian (1)
Avg boosts / post: 0.6
Top of the latest posts
Нужен ли вашему сайту WAF WAF нужен не только крупным порталам и интернет-магазинам, но и любому сайту, доступному из интернета, – вплоть до скромной страницы с услугами или обычной корпоративной визитки. Боты не делят жертв на «достойных а
Strapi 4.x – 4.26.2 & 5.x<5.48.1: CRITICAL stored XSS (CVE-2026-90561, CVSS 8.7) in WYSIWYG preview lets Author roles execute malicious scripts in higher-privileged sessions. Restrict roles & monitor vendor updates. https://radar.offseq.com
CVE-2026-75170: Unauthenticated XSS in HubCore 14.1.1 via /loginController/doLogin language param. CVSS N/A, no patch yet. Attackers can inject arbitrary JS. Audit exposure and restrict access now. Details: https://www.valtersit.com/cve/CVE
What “xss” means
WikipediaCross-site scripting (XSS) is a type of security vulnerability that can be found in some web applications. XSS attacks enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy. XSS effects vary in range from petty nuisance to significant security risk, depending on the sensitivity of the data handled by the vulnerable site and the nature of any securi
“Cross-site scripting” on Wikipedia (CC BY-SA) →#xss across platforms
every network with a public tag surfaceFollow #xss straight to each platform’s own tag page. Where a platform publishes open data we measure it above; the rest lock their numbers behind paid APIs, so we link rather than guess.
Every number above is measured from a named public API at the shown fetch time. Nothing is estimated or extrapolated. Platforms that lock their data behind paid APIs are not shown. Agents: the same numbers, as JSON, at /api/hashtags/xss