xss

45 tools and resources

NEW

Goof is a vulnerable Node.js demo application that includes a series of vulnerabilities and exploits

A collection of XSS payloads designed to turn alert(1) into P1

A tool to detect, manage and exploit Blind Cross-site scripting (XSS) vulnerabilities.

xssor2 Logo

xssor2

0 (0)

A tool for testing and exploiting Cross-Site Scripting (XSS) vulnerabilities.

A fast and simple DOM based XSS vulnerability scanner

XSSCon Logo

XSSCon

0 (0)

A simple XSS scanner tool for identifying Cross-Site Scripting vulnerabilities

xss2png Logo

xss2png

0 (0)

A tool to generate a PNG image containing a XSS payload

XSpear Logo

XSpear

0 (0)

A powerful XSS scanning and parameter analysis tool

Dalfox Logo

Dalfox

0 (0)

Dalfox is a powerful open-source XSS scanner and utility focused on automation.

SSRFire Logo

SSRFire

0 (0)

Automated SSRF finder with options for XSS and open redirects

A powerful tool for identifying and exploiting Cross-Site Scripting (XSS) vulnerabilities.

DOMdig Logo

DOMdig

0 (0)

DOM XSS scanner for Single Page Applications

Maintaining account persistence via XSS and Oauth

A simple Swagger-ui scanner that detects old versions vulnerable to various XSS attacks

docem Logo

docem

0 (0)

A tool to embed XXE and XSS payloads in various file formats

A Burp intruder extender for automating and validating XSS vulnerabilities

A better version of my xssfinder tool that scans for different types of XSS on a list of URLs.

A free and open-source tool for identifying vulnerabilities in Joomla-based websites.

A tool for detecting and exploiting vulnerabilities in web applications

A free online tool to scan for DOM-based XSS vulnerabilities in HTML, JavaScript, and CSS files.

A portable version of XSSHunter.com for finding and exploiting Cross-Site Scripting (XSS) vulnerabilities.

XSS'OR Logo

XSS'OR

0 (0)

Hack with JavaScript XSS'OR tool for encoding/decoding and various XSS related functionalities.

Rexsser Logo

Rexsser

0 (0)

A Burp plugin for identifying potential vulnerabilities in web applications

A free and open source C2 and proxy for penetration testers

Naxsi Logo

Naxsi

0 (0)

A third-party Nginx module that prevents common web attacks by reading a small subset of simple rules containing 99% of known patterns involved in website vulnerabilities.

xssmap Logo

xssmap

0 (0)

A Python-based tool for detecting XSS vulnerabilities

A blog about various cybersecurity-related topics, including home networking, compiler development, and security vulnerabilities.

A web security tool that scans for vulnerabilities and known attacks.

A demonstration site for the Acunetix Web Vulnerability Scanner, featuring intentionally vulnerable PHP code to test web application security.

DOMPurify is a fast XSS sanitizer for HTML, MathML, and SVG.

Cyclops Logo

Cyclops

0 (0)

A browser with XSS detection capabilities

A tool that automatically audits website security by crawling an entire website and identifying vulnerabilities

XSSer Logo

XSSer

0 (0)

Automatic tool for pentesting XSS attacks against different applications

A deliberately vulnerable modern day app with lots of DOM related bugs

A Burp Suite plugin for automatically adding XSS and SQL payload to fuzz

XSS Polyglot Challenge - XSS payload running in multiple contexts for testing XSS.

Cross-site scripting labs for web application security enthusiasts

A comprehensive cheatsheet for XSS filter evasion techniques.

A categorized collection of bug bounty write-ups for various vulnerabilities.

ezXSS Logo

ezXSS

0 (0)

A tool for testing Cross Site Scripting vulnerabilities

Wapiti Logo

Wapiti

0 (0)

Web-application vulnerability scanner with extensive coverage of security testing modules.

Paros Logo

Paros

0 (0)

A Java based HTTP/HTTPS proxy for assessing web application vulnerability with various useful features.