A XSS payload which runs in multiple contexts, such as <div class=''--><svg onload=alert()>'></div> and <!--'--><svg onload=alert()>. It is useful in testing XSS as it minimizes manual efforts and increases the success rate of blind XSS.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A Windows Kernel driver intentionally vulnerable to help improve skills in kernel-level exploitation.
ARM TrustZone provides a secure execution environment for applications on ARM processors.
Guidelines for secure coding in Java SE to avoid bugs that could weaken security and open holes in Java's security features.
A security-focused general purpose memory allocator providing the malloc API with hardening against heap corruption vulnerabilities.
An IDE-integrated AI security solution that detects, remediates, and educates about code vulnerabilities in real-time as developers write code.
WordPress plugin to reduce comment spam with a smarter honeypot.
An agentless API security platform that discovers, tests, and secures APIs through source code analysis without requiring traffic monitoring.
A simple Swagger-ui scanner that detects old versions vulnerable to various XSS attacks
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.