39 dépôts
Tools for detecting, managing, and exploiting XSS vulnerabilities.
Explore 39 awesome GitHub repositories matching part of an awesome list · XSS Injection. Refine with filters or upvote what's useful.
XSStrike is an automated security scanning engine designed for web application discovery, input
Advanced XSS scanner with payload analysis.
HackTools is a browser extension pentesting toolkit designed for offensive security professionals. It serves as a centralized collection of tools for generating payloads, managing penetration testing workflows, and accessing security reference materials within a web-based interface. The project provides specialized utilities for generating attack strings for XSS, SQL injection, and reverse shells to identify and exploit web vulnerabilities. It includes a data encoding and hashing utility to convert information between various formats for the purpose of bypassing security filters or verifying
Generates attack strings for XSS and SQL injection by injecting target parameters into predefined patterns.
AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co
Documents XSS injection techniques specifically for JavaScript context, including string and code block escaping.
Modlishka is a man-in-the-middle reverse proxy framework designed for automated phishing campaigns. It dynamically generates valid TLS certificates for target domains, aggregates traffic from multiple domains through a single proxy, and injects custom scripts into proxied responses. The framework operates transparently without requiring client-side certificate installation and relays two-factor authentication steps to capture secondary verification tokens. What sets Modlishka apart is its ability to automate the entire credential theft process. It logs all form submissions, headers, and cooki
Injects custom JavaScript payloads into proxied web pages using pattern-based matching rules.
Dalfox is an automated web application security tool specifically designed for discovering and verifying cross-site scripting vulnerabilities. It functions as an XSS vulnerability scanner that analyzes HTTP parameters and DOM structures to identify reflected, stored, and blind injection points. The project distinguishes itself by providing a Model Context Protocol server and a REST API, allowing artificial intelligence agents and remote interfaces to trigger and manage security scans programmatically. It utilizes a payload mutation engine and fingerprinting strategies to execute WAF evasion t
Creates injection strings using families such as HTML tags and DOM clobbering to find vulnerabilities.
XSS'OR - Hack with JavaScript.
JavaScript-based XSS exploitation tool.
Tool for testing blind Cross-Site Scripting.
XSS spider - 66/66 wavsep XSS detected
Spider for detecting XSS vulnerabilities.
The XSS Hunter service - a portable version of XSSHunter.com
Portable service for XSS payload management.
Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.
Framework for detecting and exploiting XSS.
XSS payloads designed to turn alert(1) into P1
Payloads designed to escalate XSS to critical impact.
🔱 Powerfull XSS Scanning and Parameter analysis tool&gem
XSS scanning and parameter analysis tool.
Sleepy Puppy XSS Payload Management Framework
Framework for managing XSS payloads.
A fast DOM based XSS vulnerability scanner with simplicity.
Fast scanner for DOM-based XSS.
A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.
JSONP endpoints for bypassing Content Security Policy.
A tool to embed XXE and XSS payloads in docx, odt, pptx, xlsx files (oxml_xxe on steroids)
Embeds XSS and XXE payloads into various document formats.
bXSS is a utility which can be used by bug hunters and organizations to identify Blind Cross-Site Scripting.
Utility for identifying blind Cross-Site Scripting.
BruteXSS is a tool written in python simply to find XSS vulnerabilities in web application. This tool was originally developed by Shawar Khan in CLI. I just redesigned it and made it GUI for more convienience.
Python tool for finding XSS vulnerabilities.
This is a burp intruder extender that is designed for automation and validation of XSS vulnerabilities.
Burp Intruder extender for XSS validation.