This is the data that powers the PortSwigger URL validation bypass cheat sheet.
☆60Feb 5, 2026Updated 4 months ago
Alternatives and similar repositories for url-cheatsheet-data
Users that are interested in url-cheatsheet-data are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆16Jul 17, 2024Updated last year
- Adobe Experience Manager (AEM) hacking toolkit☆114Sep 26, 2025Updated 8 months ago
- Proof of Concepts for unsafe deserialization in Ruby☆17Oct 17, 2024Updated last year
- ☆34Jan 31, 2026Updated 4 months ago
- phpfuck: using only 5 different characters to write and execute php // (^.9)☆20Nov 26, 2021Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- I created this to dump challenge for CTF that I participated☆12May 26, 2023Updated 3 years ago
- Exploit POC for CVE-2024-22026 affecting Ivanti EPMM "MobileIron Core"☆15May 15, 2024Updated 2 years ago
- Blind XSS SVG☆10Mar 27, 2023Updated 3 years ago
- Beyond XSS: Explore the Web Front-end Security Universe. A series about front-end security☆179Mar 25, 2026Updated 2 months ago
- source code of XCTF 2019 Final web task "tfboys"☆30Nov 21, 2022Updated 3 years ago
- CVE-2024-8190: Ivanti Cloud Service Appliance Command Injection☆16Sep 16, 2024Updated last year
- This repository is a collection of JavaScript gadgets that can be used to bypass XSS mitigations such as Content Security Policy (CSP) an…☆143Feb 4, 2026Updated 4 months ago
- Slim dockerized Android ndk☆12Mar 3, 2023Updated 3 years ago
- A tool for adding new lines to files, skipping duplicates and written in Rust!☆21May 8, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Archive Alchemist is a tool for creating specially crafted archives to test extraction vulnerabilities.☆236Jul 24, 2025Updated 10 months ago
- ☆13Sep 15, 2024Updated last year
- Differential testing framework for HTTP implementations☆935May 28, 2026Updated 3 weeks ago
- Content-Type Research☆667Jun 29, 2025Updated 11 months ago
- Extract GraphQL operations from javascript☆24Mar 18, 2026Updated 3 months ago
- Burp extension to fuzz/brute force GenAI/LLM prompts using a list of various payloads.☆34Sep 4, 2025Updated 9 months ago
- ☆39Dec 14, 2024Updated last year
- CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scr…☆669May 29, 2026Updated 3 weeks ago
- Testnet exchange - near identical mirror to the prod exchange | Rest API + WS + Matching Engine☆13Sep 1, 2024Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A web server designed to shut off on command to exploit DNS rebinding in Chromium-based browsers☆19Jun 9, 2023Updated 3 years ago
- A lightweight Python 3 Nmap wrapper that doesn't try too hard. Gracefully handles any Nmap command, providing access to all output types …☆17Apr 1, 2026Updated 2 months ago
- Scrape domain names from SSL certificates of arbitrary hosts☆691Mar 31, 2024Updated 2 years ago
- Challenges I created for CTFs☆25Dec 21, 2025Updated 5 months ago
- Custom Trickest Workflows☆12Oct 26, 2023Updated 2 years ago
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability☆978Dec 31, 2021Updated 4 years ago
- Exploit code for Jira Mobile Rest Plugin SSRF (CVE-2022-26135)☆85Jul 5, 2022Updated 3 years ago
- We have compiled an exhaustive list of cryptocurrency exchange hacks [ 2011 – 2022 ] – you will be amazed at how much has been stolen ove…☆12Dec 7, 2022Updated 3 years ago
- This repository provides examples of Vulnerable and Mitigated code as per CWE Categorization.☆23May 4, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A collection of pyjails!☆29May 31, 2026Updated 2 weeks ago
- Query various sources for CVE proof-of-concepts☆51Jun 1, 2023Updated 3 years ago
- A shortlist of core ServiceNow tables.☆15Oct 16, 2023Updated 2 years ago
- ☆23Jun 16, 2019Updated 7 years ago
- ☆18Feb 14, 2019Updated 7 years ago
- Extensor is a command-line tool designed to help users quickly gather URLs containing specific file extensions from a given source (e.g.,…☆10Mar 13, 2024Updated 2 years ago
- A set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard certificate in as simple a p…☆31Nov 30, 2025Updated 6 months ago