From Self-XSS to PII leakage via WAF bypass, CSRF login and window.opener abuse 19 March 2026·2310 words·11 mins