Xss Open Source Projects

Browse 304 Xss open source projects, ranked by GitHub stars. Find the most popular Xss tools and libraries.

Share your experience:✍️ Write a Post❓ Ask a Question
1-60 of 304 projects
78,355 stars

Z4nzu/hackingtool

ALL IN ONE Hacking Tool For Hackers

Metrics details
Stars78,355
21,909 stars

chaitin/SafeLine

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

Metrics details
Stars21,909
17,229 stars

cure53/DOMPurify

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:

Metrics details
Stars17,229
15,087 stars

s0md3v/XSStrike

Most advanced XSS scanner.

Metrics details
Stars15,087
14,486 stars

Hacker0x01/hacker101

Source code for Hacker101.com - a free online web and mobile security class.

Metrics details
Stars14,486
13,611 stars

qazbnm456/awesome-web-security

🐶 A curated list of Web Security materials and resources.

Metrics details
Stars13,611
12,119 stars

nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters

A list of resources for those interested in getting started in bug bounties

Metrics details
Stars12,119
11,658 stars

chaitin/xray

一款长亭自研的完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档

Metrics details
Stars11,658
11,377 stars

jhy/jsoup

jsoup: the Java HTML parser, built for HTML editing, cleaning, scraping, and XSS safety.

Metrics details
Stars11,377
7,115 stars

infoslack/awesome-web-hacking

A list of web application security

Metrics details
Stars7,115
6,366 stars

reddelexc/hackerone-reports

Top disclosed reports from HackerOne

Metrics details
Stars6,366
6,034 stars

devanshbatham/Awesome-Bugbounty-Writeups

A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference

Metrics details
Stars6,034
5,750 stars

dromara/lamp-cloud

[灯灯]微服务中后台快速开发平台,支持jdk21、jdk17、jdk8,专注于多租户、开放平台解决方案,亦可作为普通项目(非SaaS架构)的基础开发框架使用,目前已实现插拔式数据库隔离、SCHEMA隔离、字段隔离 等租户隔离方案。

Metrics details
Stars5,750
5,318 stars

leizongmin/js-xss

Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist

Metrics details
Stars5,318
5,182 stars

payloadbox/xss-payload-list

🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List

Metrics details
Stars5,182
5,132 stars

s0md3v/AwesomeXSS

Awesome XSS stuff

Metrics details
Stars5,132
5,130 stars

hahwul/dalfox

🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.

Metrics details
Stars5,130
5,110 stars

scinfu/SwiftSoup

SwiftSoup: Pure Swift HTML Parser, with best of DOM, CSS, and jquery (Supports Linux, iOS, Mac, tvOS, watchOS)

Metrics details
Stars5,110
4,450 stars

zhuifengshaonianhanlu/pikachu

一个好玩的Web安全-漏洞测试平台

Metrics details
Stars4,450
4,303 stars

CHYbeta/Web-Security-Learning

Web-Security-Learning

Metrics details
Stars4,303
4,224 stars

ngalongc/bug-bounty-reference

Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature

Metrics details
Stars4,224
4,036 stars

Arachni/arachni

Web Application Security Scanner Framework

Metrics details
Stars4,036
3,966 stars

foospidy/payloads

Git All the Payloads! A collection of web attack payloads.

Metrics details
Stars3,966
3,698 stars

microcosm-cc/bluemonday

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Metrics details
Stars3,698
2,919 stars

Kitsun3Sec/Pentest-Cheat-Sheets

A collection of snippets of codes and commands to make your life easier!

Metrics details
Stars2,919
2,757 stars

Rich-Harris/devalue

Gets the job done when JSON.stringify can't

Metrics details
Stars2,757
2,450 stars

c0ny1/vulstudy

使用docker快速搭建各大漏洞靶场,目前可以一键搭建17个靶场。

Metrics details
Stars2,450
2,378 stars

terjanq/Tiny-XSS-Payloads

A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me

Metrics details
Stars2,378
2,323 stars

ssl/ezXSS

ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.

Metrics details
Stars2,323
2,240 stars

Ascotbe/Medusa

:cat2:Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

Metrics details
Stars2,240
2,223 stars

evilcos/xssor2

XSS'OR - Hack with JavaScript.

Metrics details
Stars2,223
2,109 stars

tom0li/collection-document

Collection of quality safety articles. Awesome articles.

Metrics details
Stars2,109
2,033 stars

0xSobky/HackVault

A container repository for my public web hacks!

Metrics details
Stars2,033
1,926 stars

ReAbout/web-sec

WEB安全手册(红队安全技能栈),漏洞理解,漏洞利用,代码审计和渗透测试总结。【持续更新】

Metrics details
Stars1,926
1,822 stars

wapiti-scanner/wapiti

Web vulnerability scanner written in Python3

Metrics details
Stars1,822
1,812 stars

1N3/BlackWidow

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

Metrics details
Stars1,812
1,768 stars

SecWiki/CMS-Hunter

CMS漏洞测试用例集合

Metrics details
Stars1,768
1,766 stars

404notf0und/AI-for-Security-Learning

安全场景、基于AI的安全算法和安全数据分析业界实践

Metrics details
Stars1,766
1,743 stars

DanMcInerney/xsscrapy

XSS spider - 66/66 wavsep XSS detected

Metrics details
Stars1,743
1,701 stars

mganss/HtmlSanitizer

Cleans HTML to avoid XSS attacks

Metrics details
Stars1,701
1,698 stars

B3nac/Android-Reports-and-Resources

A big list of Android Hackerone disclosed reports and other resources.

Metrics details
Stars1,698
1,682 stars

Tencent/Biny

Biny is a tiny, high-performance PHP framework for web applications

Metrics details
Stars1,682
1,639 stars

xdavidhu/awesome-google-vrp-writeups

🐛 A list of writeups from the Google VRP Bug Bounty program

Metrics details
Stars1,639
1,636 stars

BlackFan/client-side-prototype-pollution

Prototype Pollution and useful Script Gadgets

Metrics details
Stars1,636
1,615 stars

wwong99/pentest-notes

Metrics details
Stars1,615
1,579 stars

AlisamTechnology/ATSCAN

Advanced dork Search & Mass Exploit Scanner

Metrics details
Stars1,579
1,570 stars

v3n0m-Scanner/V3n0M-Scanner

Popular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulns

Metrics details
Stars1,570
1,556 stars

mandatoryprogrammer/xsshunter

The XSS Hunter service - a portable version of XSSHunter.com

Metrics details
Stars1,556
1,503 stars

nemesida-waf/waf-bypass

Check your WAF before an attacker does

Metrics details
Stars1,503
1,456 stars

epsylon/xsser

Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.

Metrics details
Stars1,456
1,443 stars

botesjuan/Burp-Suite-Certified-Practitioner-Exam-Study

Burp Suite Certified Practitioner Exam Study

Metrics details
Stars1,443
1,437 stars

t3l3machus/toxssin

An XSS exploitation command-line interface and payload generator.

Metrics details
Stars1,437
1,419 stars

xiaoZ-hc/redtool

日常积累的一些红队工具及自己写的脚本,更偏向于一些diy的好用的工具,并不是一些比较常用的msf/awvs/xray这种

Metrics details
Stars1,419
1,401 stars

hakluke/weaponised-XSS-payloads

XSS payloads designed to turn alert(1) into P1

Metrics details
Stars1,401
1,363 stars

hahwul/XSpear

🔱 Powerfull XSS Scanning and Parameter analysis tool&gem

Metrics details
Stars1,363
1,289 stars

nette/latte

☕ Latte: the safest & truly intuitive templates for PHP. Engine for those who want the most secure PHP sites.

Metrics details
Stars1,289
1,252 stars

zardus/wargame-nexus

A sorted and updated list of security wargame sites.

Metrics details
Stars1,252
1,250 stars

m4n3dw0lf/pythem

pentest framework

Metrics details
Stars1,250
1,214 stars

elkokc/reflector

Burp plugin able to find reflected XSS on page in real-time while browsing on site

Metrics details
Stars1,214
1,157 stars

masatokinugawa/filterbypass

Browser's XSS Filter Bypass Cheat Sheet

Metrics details
Stars1,157
1-60 of 304 projects
Get A Weekly Email With Trending Xss Projects
Stay updated on Xss plus related topics you pick below.

Copyright 2018-2026 Awesome Open Source.  All rights reserved.