Xss Open Source Projects
Browse 304 Xss open source projects, ranked by GitHub stars. Find the most popular Xss tools and libraries.
Z4nzu/hackingtool
ALL IN ONE Hacking Tool For Hackers
Metrics details
| Stars | 78,355 |
chaitin/SafeLine
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
Metrics details
| Stars | 21,909 |
cure53/DOMPurify
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
Metrics details
| Stars | 17,229 |
s0md3v/XSStrike
Most advanced XSS scanner.
Metrics details
| Stars | 15,087 |
Hacker0x01/hacker101
Source code for Hacker101.com - a free online web and mobile security class.
Metrics details
| Stars | 14,486 |
qazbnm456/awesome-web-security
🐶 A curated list of Web Security materials and resources.
Metrics details
| Stars | 13,611 |
nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters
A list of resources for those interested in getting started in bug bounties
Metrics details
| Stars | 12,119 |
chaitin/xray
一款长亭自研的完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档
Metrics details
| Stars | 11,658 |
jhy/jsoup
jsoup: the Java HTML parser, built for HTML editing, cleaning, scraping, and XSS safety.
Metrics details
| Stars | 11,377 |
infoslack/awesome-web-hacking
A list of web application security
Metrics details
| Stars | 7,115 |
reddelexc/hackerone-reports
Top disclosed reports from HackerOne
Metrics details
| Stars | 6,366 |
devanshbatham/Awesome-Bugbounty-Writeups
A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference
Metrics details
| Stars | 6,034 |
dromara/lamp-cloud
[灯灯]微服务中后台快速开发平台,支持jdk21、jdk17、jdk8,专注于多租户、开放平台解决方案,亦可作为普通项目(非SaaS架构)的基础开发框架使用,目前已实现插拔式数据库隔离、SCHEMA隔离、字段隔离 等租户隔离方案。
Metrics details
| Stars | 5,750 |
leizongmin/js-xss
Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist
Metrics details
| Stars | 5,318 |
payloadbox/xss-payload-list
🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
Metrics details
| Stars | 5,182 |
s0md3v/AwesomeXSS
Awesome XSS stuff
Metrics details
| Stars | 5,132 |
hahwul/dalfox
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
Metrics details
| Stars | 5,130 |
scinfu/SwiftSoup
SwiftSoup: Pure Swift HTML Parser, with best of DOM, CSS, and jquery (Supports Linux, iOS, Mac, tvOS, watchOS)
Metrics details
| Stars | 5,110 |
zhuifengshaonianhanlu/pikachu
一个好玩的Web安全-漏洞测试平台
Metrics details
| Stars | 4,450 |
CHYbeta/Web-Security-Learning
Web-Security-Learning
Metrics details
| Stars | 4,303 |
ngalongc/bug-bounty-reference
Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature
Metrics details
| Stars | 4,224 |
Arachni/arachni
Web Application Security Scanner Framework
Metrics details
| Stars | 4,036 |
foospidy/payloads
Git All the Payloads! A collection of web attack payloads.
Metrics details
| Stars | 3,966 |
microcosm-cc/bluemonday
bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS
Metrics details
| Stars | 3,698 |
Kitsun3Sec/Pentest-Cheat-Sheets
A collection of snippets of codes and commands to make your life easier!
Metrics details
| Stars | 2,919 |
Rich-Harris/devalue
Gets the job done when JSON.stringify can't
Metrics details
| Stars | 2,757 |
c0ny1/vulstudy
使用docker快速搭建各大漏洞靶场,目前可以一键搭建17个靶场。
Metrics details
| Stars | 2,450 |
terjanq/Tiny-XSS-Payloads
A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me
Metrics details
| Stars | 2,378 |
ssl/ezXSS
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
Metrics details
| Stars | 2,323 |
Ascotbe/Medusa
:cat2:Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中
Metrics details
| Stars | 2,240 |
evilcos/xssor2
XSS'OR - Hack with JavaScript.
Metrics details
| Stars | 2,223 |
tom0li/collection-document
Collection of quality safety articles. Awesome articles.
Metrics details
| Stars | 2,109 |
0xSobky/HackVault
A container repository for my public web hacks!
Metrics details
| Stars | 2,033 |
ReAbout/web-sec
WEB安全手册(红队安全技能栈),漏洞理解,漏洞利用,代码审计和渗透测试总结。【持续更新】
Metrics details
| Stars | 1,926 |
wapiti-scanner/wapiti
Web vulnerability scanner written in Python3
Metrics details
| Stars | 1,822 |
1N3/BlackWidow
A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.
Metrics details
| Stars | 1,812 |
SecWiki/CMS-Hunter
CMS漏洞测试用例集合
Metrics details
| Stars | 1,768 |
404notf0und/AI-for-Security-Learning
安全场景、基于AI的安全算法和安全数据分析业界实践
Metrics details
| Stars | 1,766 |
DanMcInerney/xsscrapy
XSS spider - 66/66 wavsep XSS detected
Metrics details
| Stars | 1,743 |
mganss/HtmlSanitizer
Cleans HTML to avoid XSS attacks
Metrics details
| Stars | 1,701 |
B3nac/Android-Reports-and-Resources
A big list of Android Hackerone disclosed reports and other resources.
Metrics details
| Stars | 1,698 |
Tencent/Biny
Biny is a tiny, high-performance PHP framework for web applications
Metrics details
| Stars | 1,682 |
xdavidhu/awesome-google-vrp-writeups
🐛 A list of writeups from the Google VRP Bug Bounty program
Metrics details
| Stars | 1,639 |
BlackFan/client-side-prototype-pollution
Prototype Pollution and useful Script Gadgets
Metrics details
| Stars | 1,636 |
wwong99/pentest-notes
Metrics details
| Stars | 1,615 |
AlisamTechnology/ATSCAN
Advanced dork Search & Mass Exploit Scanner
Metrics details
| Stars | 1,579 |
v3n0m-Scanner/V3n0M-Scanner
Popular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulns
Metrics details
| Stars | 1,570 |
mandatoryprogrammer/xsshunter
The XSS Hunter service - a portable version of XSSHunter.com
Metrics details
| Stars | 1,556 |
nemesida-waf/waf-bypass
Check your WAF before an attacker does
Metrics details
| Stars | 1,503 |
epsylon/xsser
Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.
Metrics details
| Stars | 1,456 |
botesjuan/Burp-Suite-Certified-Practitioner-Exam-Study
Burp Suite Certified Practitioner Exam Study
Metrics details
| Stars | 1,443 |
t3l3machus/toxssin
An XSS exploitation command-line interface and payload generator.
Metrics details
| Stars | 1,437 |
xiaoZ-hc/redtool
日常积累的一些红队工具及自己写的脚本,更偏向于一些diy的好用的工具,并不是一些比较常用的msf/awvs/xray这种
Metrics details
| Stars | 1,419 |
hakluke/weaponised-XSS-payloads
XSS payloads designed to turn alert(1) into P1
Metrics details
| Stars | 1,401 |
hahwul/XSpear
🔱 Powerfull XSS Scanning and Parameter analysis tool&gem
Metrics details
| Stars | 1,363 |
nette/latte
☕ Latte: the safest & truly intuitive templates for PHP. Engine for those who want the most secure PHP sites.
Metrics details
| Stars | 1,289 |
zardus/wargame-nexus
A sorted and updated list of security wargame sites.
Metrics details
| Stars | 1,252 |
m4n3dw0lf/pythem
pentest framework
Metrics details
| Stars | 1,250 |
elkokc/reflector
Burp plugin able to find reflected XSS on page in real-time while browsing on site
Metrics details
| Stars | 1,214 |
masatokinugawa/filterbypass
Browser's XSS Filter Bypass Cheat Sheet
Metrics details
| Stars | 1,157 |
