There are 12 repositories under cross-site-scripting topic.
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
w3af: web application attack and audit framework, the open source web vulnerability scanner.
An XSS exploitation command-line interface and payload generator.
bXSS is a utility which can be used by bug hunters and organizations to identify Blind Cross-Site Scripting.
Build Content-Security-Policy headers from a JSON file (or build them programmatically)
Tips on how to write exploit scripts (faster!)
Blind XSS Scanner is a tool that can be used to scan for blind XSS vulnerabilities in web applications.
Egyscan The Best web vulnerability scanner; it's a multifaceted security powerhouse designed to fortify your web applications against malicious threats. Let's delve into the tasks and functions that make Egyscan an indispensable tool in your security arsenal:
this repository is a docker containing some "XSS vulnerability" challenges and bypass examples.
phpMyAdmin XSS
NLP model and tech for cyber security tasks
XsSCan | Web Application XSS Scanner | Coded By Sir.4m1R [Mr.Hidden]
Cross-Site Scripting (XSS) injects malicious scripts into trusted websites via user input. Attacker-sent scripts run in users' browsers, accessing sensitive data, cookies, and even altering HTML content. Widespread due to input validation lapses.
XSSearch is a comprehensive reflected XSS tool built on selenium framework in python language. It contains more than 3000 payloads for automating XSS attacks and validating XSS endpoint
Simple machine learning based web application firewall (WAF) created in python
JSSCM detects expired domains for Stored XSS exploitation during browsing.
Simple API for storing all incoming XSS requests and various XSS templates.
Deep Security's APIs make it simple to integration with a variety of AWS Services
PHP Cookie Stealing Scripts for use in XSS
A PHP application which runs on Heroku and dumps web site outputs including JavaScript generated contents.
Exotic and uncommon XSS Vectors to hit the target as quickly as possible.
This project contains datasets for Cross Site Scripting (XSS), SQL, and LDAP injections. The project also contains the Matlab code for creating SVM, K-NN, Random Forest, and Neural Networks classifiers to detect Web applications attacks.
A Web application firewall to monitor, analyze and block traffic, built with Python
Vulnerable Web application made with PHP/SQL designed to help new web testers gain some experience and test DAST tools for identifying web vulnerabilities. Containing some of the most well-known vulnerabilities such as SQL, cross-site scripting (XSS), OS command injections, our intention to expand more vulnerabilities for learning purposes.
🔱 Ronin the Shogun, WebApp parameter analysis and fuzzer for XSS and SSRF.
A comprehensive toolkit for ethical security testing of Cross-Site Scripting (XSS) vulnerabilities. Features a CLI tool for automated payload spraying across web targets and a server component for callback handling with persistent storage, analytics dashboard, and multi-channel notifications.