There are 18 repositories under xss-vulnerability topic.
🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
An XSS exploitation command-line interface and payload generator.
MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this saving the results obtained in an organized way in directories and with various formats.
XssPayload List . Usage:
swiss army knife for hackers
A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.
JAVA 漏洞靶场 (Vulnerability Environment For Java)
Another web vulnerabilities scanner, this extension works on Chrome and Opera
OWASP Vulnerable Web Application Project https://github.com/hummingbirdscyber
Automating XSS using Bash
XRCross is a Reconstruction, Scanner, and a tool for penetration / BugBounty testing. This tool was built to test (XSS|SSRF|CORS|SSTI|IDOR|RCE|LFI|SQLI) vulnerabilities
Demo of a Vue.js app that mixes both clientside templates and serverside templates leading to an XSS vulnerability
DOMXSS Scanner is an online tool to scan source code for DOM based XSS vulnerabilities
Collect XSS vulnerable parameters from entire domain.
XSSRocket it is a tool designed for offensive security and XSS (Cross-Site Scripting) attacks.
XSS scanner that detects Cross-Site Scripting vulnerabilities in website by injecting malicious scripts
this repository is a docker containing some "XSS vulnerability" challenges and bypass examples.
XSS Payload without Anything.
XsSCan | Web Application XSS Scanner | Coded By Sir.4m1R [Mr.Hidden]
A vulnerability fuzzing tool written in bash, it contains the most commonly used tools to perform vulnerability scan
XSS cookie stealer using JavaScript and PHP
Cross-Site Scripting (XSS) injects malicious scripts into trusted websites via user input. Attacker-sent scripts run in users' browsers, accessing sensitive data, cookies, and even altering HTML content. Widespread due to input validation lapses.
PoC - Exploit Delivery via Steganography and Polyglots, CVE-2014-0282
PoC for XSS in org.webjars:swagger-ui [3.14.2, 3.36.2]
This repo contains different variants of Bug Bounty & Security & Pentest & Tech related Articles
Simple-XSS is a multiplatform cross-site scripting (XSS) vulnerability exploitation tool.
Welcome SecToolkit repository! This is a comprehensive collection of cybersecurity and bug bounty hunting topics. Here, you'll find a variety of resources, notes, and practical projects aimed at enhancing knowledge and skills in identifying and mitigating security vulnerabilities.
Light weight library for Filter the Cross-site scripting in request For Spring Framwork / Spring-Boot, logic can be use for servlet based(without using spring framework) application