A comprehensive WordPress vulnerability scanner and exploitation framework for authorized penetration testing. This tool automatically detects and exploits multiple WordPress security vulnerabilities (CVEs) to help security professionals identify and patch weaknesses.
☆76May 21, 2026Updated 4 months ago
Alternatives and similar repositories for Mephisto
Users that are interested in Mephisto are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Full and complete RCE exploit for Magento Polyshell☆30Apr 9, 2026Updated 5 months ago
- WordPress XML-RPC & WP-Login Bruteforce + Auto Uploader Powerful asynchronous bruteforce tool for WordPress sites via wp-login.php and …☆25Apr 22, 2025Updated last year
- PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0☆21Jul 20, 2026Updated 2 months ago
- Tool to bypass 40X response codes.☆48Sep 18, 2022Updated 4 years ago
- Beelzebub all in one Hacking Tools, Shell finder, Zone-H Grabber, ReverseIP, SMTP Finder, XMLRPC BF and more☆57May 27, 2025Updated last year
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- SSRFHunter☆18Jan 17, 2026Updated 8 months ago
- Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, …☆184May 12, 2026Updated 4 months ago
- My Main App Hacking CheckList☆35Jun 20, 2026Updated 3 months ago
- Burp Suite extension + port-based highlighter: dedupes HTTP history into a live unique-request feed and color-codes attacker/victim traff…☆14Aug 14, 2026Updated last month
- CVE-2025-55182-bypass-waf☆31Jan 8, 2026Updated 8 months ago
- Kali Linux Polyglot Framework for Autonomous Pentesting/Cyber Security☆137Aug 16, 2026Updated last month
- FortiSandbox RCE Scanner — CVE-2026-39808☆26Apr 21, 2026Updated 5 months ago
- NextSSRF — CVE-2026-44578 Scanner & Exploit ║ ║ Next.js WebSocket Upgrade Handler SSRF☆77May 15, 2026Updated 4 months ago
- Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier☆244Sep 11, 2026Updated 3 weeks ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A shellcode loader generator with support for multiple injection techniques, built for red team engagements.☆102Jul 1, 2026Updated 3 months ago
- Stealth Windows keylogger.☆58Jan 11, 2026Updated 8 months ago
- Apkx-Hunter is an Android Static Analysis Framework in Debian Package written entirely in C with OWASP MASVS scanning with 15 categories …☆94Sep 15, 2026Updated 2 weeks ago
- Nuclei templates which I wrote myself☆10Jan 8, 2022Updated 4 years ago
- Passive leak enumeration tool.☆598Updated this week
- The ultimate pentesting companion. Keep all your pentesting artifacts in one place.☆70Jul 27, 2026Updated 2 months ago
- Curated Linux LPE corpus — 28 modules from 2016 to 2026, with detection rules. One command, safest-first root: skeletonkey --auto --i-kno…☆25Aug 31, 2026Updated last month
- xnew is a fast, low-memory CLI that appends only unique lines to files. Built in Go for large datasets, it streams input efficiently and …☆30May 23, 2026Updated 4 months ago
- ☆37May 5, 2026Updated 4 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- CVE-2026-21643☆18Mar 28, 2026Updated 6 months ago
- A collection of awesome one-liners for bug bounty hunting.☆60Apr 12, 2026Updated 5 months ago
- Burp Suite extension — passively detects secrets, API keys, credentials, JWTs & PII in HTTP traffic. 160+ detection rules, bulk scan, ent…☆56Aug 24, 2026Updated last month
- A tool that helps you find the real IP addresses hiding behind Cloudflare.☆647Jul 6, 2026Updated 2 months ago
- Burp_Suite-Antigravity_AI-Bug_Bounty_Hunter☆64Feb 9, 2026Updated 7 months ago
- Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest☆385Updated this week
- A comprehensive Python-based OSINT (Open Source Intelligence) tool for email and phone number verification with breach detection, social …☆73Sep 9, 2025Updated last year
- Fortinet FortiClientEMS improper access control☆37Apr 20, 2026Updated 5 months ago
- GarudRecon automates domain recon with top open-source tools to discover assets, enumerate subdomains, and detect XSS, SQLi, LFI, RCE & m…☆273Mar 28, 2026Updated 6 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Detection template for CVE-2025-8110☆22Dec 11, 2025Updated 9 months ago
- Run PowerShell command without invoking powershell.exe☆27Apr 9, 2026Updated 5 months ago
- It serves as a practical guide for security researchers to identify and test WordPress targets effectively during bug bounty hunting.☆27Jul 19, 2026Updated 2 months ago
- mattew crawls target websites, extracts hidden attack surface, runs security analysis, fingerprints technology, and generates professiona…☆17Jul 2, 2026Updated 3 months ago
- TokenTwin Checker — Dual Token BAC/IDOR Tester for Burp Suite☆97Aug 24, 2026Updated last month
- SpotifyC2 is a cybersecurity research project that demonstrates cloud-based command communication using Spotify playlists for command ret…☆180Jun 29, 2026Updated 3 months ago
- ☆40Jun 4, 2026Updated 4 months ago