An open API service indexing awesome lists of open source software.

Projects in Awesome Lists tagged with xss-exploitation

A curated list of projects in awesome lists tagged with xss-exploitation .

https://github.com/ssl/ezxss

ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.

alert blind blind-xss bug bugbounty easy easy-to-use payload penetration-testing php redteam redteaming test xss xss-attacks xss-detection xss-exploitation xss-injection xss-scanner xss-vulnerability

Last synced: 14 May 2025

https://github.com/ssl/ezXSS

ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.

alert blind blind-xss bug bugbounty easy easy-to-use payload penetration-testing php redteam redteaming test xss xss-attacks xss-detection xss-exploitation xss-injection xss-scanner xss-vulnerability

Last synced: 02 Apr 2025

https://github.com/ajinabraham/owasp-xenotix-xss-exploit-framework

OWASP Xenotix XSS Exploit Framework is an advanced Cross Site Scripting (XSS) vulnerability detection and exploitation framework.

dom-xss exploitation-framework xenotix xss xss-detection xss-exploitation xss-scanner

Last synced: 05 Apr 2025

https://github.com/kleiton0x00/ppmap

A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.

bug-bounty bugbounty bugbounty-tool cybersecurity infosec prototype-pollution xss xss-detection xss-exploitation xss-vulnerability

Last synced: 05 Apr 2025

https://github.com/varbaek/xsser

From XSS to RCE 2.75 - Black Hat Europe Arsenal 2017 + Extras

xss xss-attacks xss-exploitation xss-injection xss-poc

Last synced: 02 Apr 2025

https://github.com/tegal1337/0l4bs

Cross-site scripting labs for web application security enthusiasts

bugbounty labs xss xss-exploitation xss-vulnerability

Last synced: 09 Apr 2025

https://github.com/raz-varren/xsshell

An XSS reverse shell framework

golang javascript reverse-shell xss xss-exploitation

Last synced: 29 Jun 2025

https://github.com/Jewel591/xssmap

XSSMap 是一款基于 Python3 开发用于检测 XSS 漏洞的工具

penetration-testing pentesting python3 sqlmap xss xss-attacks xss-detection xss-exploitation xss-scanner xss-vulnerability

Last synced: 02 Apr 2025

https://github.com/shadow-workers/shadow-workers

Shadow Workers is a free and open source C2 and proxy designed for penetration testers to help in the exploitation of XSS and malicious Service Workers (SW)

c2 penetration-testing-tools proxy service-worker xss-exploitation

Last synced: 02 Apr 2025

https://github.com/ihebski/XSS-Payloads

Collection of XSS Payloads for fun and profit

bugbounty bughunter javascript payloads pentesting xss-exploitation xss-payloads

Last synced: 28 Sep 2025

https://github.com/r0x4r/d4rkxss

A list of useful payloads and Bypass for Web Application Security and Bug Bounty/CTF

bugbounty bughunter bughunting ethical-hacking hacking javascript xss-exploitation xss-filter xss-vulnerability

Last synced: 22 Aug 2025

https://github.com/R0X4R/D4rkXSS

A list of useful payloads and Bypass for Web Application Security and Bug Bounty/CTF

bugbounty bughunter bughunting ethical-hacking hacking javascript xss-exploitation xss-filter xss-vulnerability

Last synced: 11 Jul 2025

https://github.com/blackhatethicalhacking/XSSRocket

XSSRocket it is a tool designed for offensive security and XSS (Cross-Site Scripting) attacks.

bugbounty cybersecurity hacking infosec offensive penetration-testing pentesting xss xss-attacks xss-detection xss-exploitation xss-scanner xss-vulnerability

Last synced: 18 Jul 2025

https://github.com/blackhatethicalhacking/xssrocket

XSSRocket it is a tool designed for offensive security and XSS (Cross-Site Scripting) attacks.

bugbounty cybersecurity hacking infosec offensive penetration-testing pentesting xss xss-attacks xss-detection xss-exploitation xss-scanner xss-vulnerability

Last synced: 14 Jul 2025

https://github.com/trixsec/waymap

Waymap is a fast and optimized web vulnerability scanner built for penetration testers. It helps in identifying vulnerabilities by testing against various payloads.

command-injection command-injection-scanner command-line-tool exploitation-framework hacking lfi-exploitation open-redirect-detection python scanner sql-scanner sqli-scanner sqlinjection sqlmap ssti trixsec waymap website-hacking website-hacking-tool xss-detection xss-exploitation

Last synced: 10 Apr 2025

https://github.com/redcode-labs/poxsson

A framework for easy payloads development and deployment, collection of customizable XSS payloads

python tool xss xss-attacks xss-exploitation

Last synced: 09 Apr 2025

https://github.com/dragthor/xss-scanner

Cross-Site Scripting (XSS) scanner. This tool helps to find possible XSS vulnerabilities. Cross platform - macOS, Linux, and Windows.

xss xss-detection xss-exploitation xss-scanner xss-testing xss-vulnerability

Last synced: 27 Feb 2026

https://github.com/paulveillard/cybersecurity-web-application-labs

An ongoing & curated collection of awesome software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidelines and important resources about Web Application Security Labs in Cybersecurity

labs sqlinject-defense sqlinjection web-application-framework web-security-gateway web-security-research xss xss-exploitation xss-payloads xss-scanner xss-vulnerability

Last synced: 16 Oct 2025

https://github.com/esonhugh/proxyinbrowser

Open Source XSS exploitation tool. using http proxy to access the browser which executed this project. [Engineering Experimental]

browser cors-proxy golang hacktool http-proxy mitm mitmproxy proxy-server tools typescript xss xss-exploitation

Last synced: 16 Apr 2025

https://github.com/aw-junaid/web-security

Master web security: OWASP Top 10, XSS, SQLi, CSRF, and secure coding practices. Includes labs, tools, and examples for secure web development.

csrf hacking hacking-tool owasp penetration-testing websecurity xss xss-exploitation xss-vulnerability

Last synced: 24 Feb 2026

https://github.com/faizan-khanx/xss-detector

XSS-DETECTOR is a Python tool for identifying XSS vulnerabilities in web apps by automating payload injections. It aids security researchers and developers in spotting potential flaws and is valuable in digital forensics for decoding and analyzing encoded payloads used in XSS attacks.

cyber-security cybersecurity ethicalfaizan hacking hacking-tool xss-detection xss-exploitation xss-vulnerability

Last synced: 12 Oct 2025

https://github.com/darkstarbdx/xssblitz

XSSblitz ⚡ is a blazing-fast 🚀 and modern 🖥️ XSS vulnerability scanner 🔍, designed to help you effortlessly uncover 🕵️‍♂️ and exploit XSS vulnerabilities 💥 with ease.

bugbounty cross-site-scripting ethical-hacking security-testing security-tools tools vulnerability-exploitation vulnerability-scanner xss xss-detection xss-exploitation xss-vulnerability

Last synced: 03 Aug 2025

https://github.com/aw-junaid/php-web-security

Secure PHP web apps with best practices: SQLi prevention, XSS protection, CSRF tokens, password hashing, and secure session management.

hacking hacking-tool php xss xss-exploitation xss-vulnerability

Last synced: 14 Apr 2025

https://github.com/volkansah/sqlp-edu

Example Python script that demonstrates a simple example of a Cross-Site Scripting (XSS) exploit for educational purposes only. This script is intended to be used responsibly, for learning and understanding the security implications of XSS attacks, and should not be used for any illegal or unethical activities.

bypass cross-site-scripting ehtical-hacking-tools exploit exploitation explotation hacking hacking-tool hacking-tools penetration-testing pentesting phishing python security sql-xss vulnerability xss xss-attacks xss-exploitation xss-injection

Last synced: 11 Jul 2025

https://github.com/polarspetroll/js-keylogger

javascript cliend-side keylogger

javascript keylogger xss xss-exploitation

Last synced: 15 Mar 2026

https://github.com/fear2o/h4ckweb

H4ckWeb is a powerful, advanced tool designed for testing web vulnerabilities, including SQL injection and Cross-Site Scripting (XSS). Built with both beginners and advanced users in mind, H4ckWeb allows security professionals and ethical hackers to quickly identify and exploit common web application flaws.

hacking hacking-tool hacking-tools online python python3 sql xss xss-attacks xss-detection xss-exploitation xss-vulnerability

Last synced: 18 Aug 2025

https://github.com/fear2o/scanshield

ScanShield is an advanced vulnerability scanner built to identify common web security flaws such as SQL Injection, XSS, LFI, RFI, directory listing issues, and security header misconfigurations.

ethical-hacking hacking hacking-tool lfi-detection lfi-exploit lfi-exploitation lfi-vulnerability python python3 sql vulnerabilities vulnerability vulnerability-detection vulnerability-scanners xss xss-attacks xss-detection xss-exploitation xss-vulnerability

Last synced: 23 Apr 2025

https://github.com/gsmith257-cyber/cookie-monster-xss

Generate a obfuscated XSS payload to steal cookies

obfuscation xss xss-exploitation

Last synced: 15 Mar 2026

https://github.com/mertbingol0/xss-scanner

Xss-scanner, kullanıcıdan aldığı url içeriğindeki formu taramak için, sitedeki tum html'i bs4 ve request yardimiyla ceker ve de duzenler. Ardindan html icerisinden form kismini alir, onun icerisinden de input taglarini ceker...

xss xss-detection xss-exploitation xss-payload xss-scanner

Last synced: 28 May 2026

https://github.com/vheidari/wpxssmaker

A online wordpress xss maker , only wordpress version 3.xx

hack wordpress xss xss-attacks xss-exploitation xss-injection xss-vulnerability

Last synced: 01 Apr 2025

https://github.com/drakota/xss-sandbox

A purposely flawed chat application to test the effects of cross site-scripting in a safe environment.

chat nodejs pentesting security xss xss-exploitation xss-vulnerability

Last synced: 10 May 2026

https://github.com/hackfutsec/xssdump

**XssDump** is a Python-based XSS (Cross-Site Scripting) vulnerability scanner designed to test web applications for potential XSS vulnerabilities. The script performs automated testing by injecting payloads into URLs and analyzing HTTP responses to check for the presence of malicious scripts.

cybersecurity hacking payloads payloadsallthethings python xss xss-attacks xss-detection xss-exploitation xss-vulnerability

Last synced: 12 May 2026

https://github.com/asmroyal/hydra

Hydra XSS Injector for every website (bypasses cloudflare blacklist)

xss xss-attacks xss-detection xss-exploitation xss-vulnerability

Last synced: 25 Jan 2026

https://github.com/darkpurple141/xss-test

A utility to test the success of xss payloads on a target website. Use responsibly.

penetration-testing pentesting python3 security tools websec xss xss-exploitation

Last synced: 08 Sep 2025

https://github.com/mvpee/42-darkly

This project is an introduction to cyber security in the field of the Web

42 cyber darkly sqlinjection xss-exploitation

Last synced: 31 Dec 2025

https://github.com/galihap76/python-reflected-xss-exploit

Little Python script for reflected XSS exploit targeting web applications.

exploit exploitation hacking python web-hacking xss-exploitation xss-vulnerability

Last synced: 30 Jul 2026

https://github.com/michaelsdavid/xss_code_injector

An XSS code injector script that generates an alert popup box in the browser, part of the Python and Ethical Hacking course by ZSecurity (requires HTTP only, all caches cleared)

ethical-hacking python python27 scapy xss xss-exploitation

Last synced: 14 Mar 2026

https://github.com/zaidalissawi/ecommerce-website-php

An intentionally vulnerable ecommerce website project built with PHP and MySQL for educational and ethical hacking purposes. This project is designed to help security enthusiasts and penetration testers learn and practice web application security testing in a safe and legal environment.

csrf css html js php xss xss-exploitation

Last synced: 02 Apr 2026

https://github.com/utfpr-cesc/csrf-xss-rogue-website

Rogue website to demonstrate CSRF and XSS attacks.

cookies csrf csrf-exploitation javascript sessions xss xss-exploitation

Last synced: 11 Jun 2025

https://github.com/povzayd/xss-labs

This is an intentionally vuln webpage designed to practice XSS.

webpentesting xss xss-attacks xss-exploitation xss-injection xss-poc xss-vulnerability

Last synced: 11 Feb 2026

https://github.com/0xh4ty/jamxss

JAMXSS (Just A Monster XSS Scanner) is a state-of-the-art tool designed to test for reflected XSS (Cross-Site Scripting) vulnerabilities in web applications. By leveraging machine learning, JAMXSS offers an innovative approach to detecting and mitigating security risks with exceptional accuracy and efficiency.

ai-xss-scanner ml-powered-xss-scanner ml-xss-scanner reflected-xss reflected-xss-vulnerabilities xss-attacks xss-detection xss-exploitation xss-injection xss-scanner xss-vulnerability

Last synced: 05 Apr 2025

https://github.com/xamiron/csrf-vulnerability

In this repository, I discuss the CSRF vulnerability and how to do execute a CSRF attack.

burpsuite csrf csrf-attacks csrf-form csrf-protection security xss-exploitation

Last synced: 13 Feb 2026