kevin-mizu / GMSGadgetView external linksLinks
This repository is a collection of JavaScript gadgets that can be used to bypass XSS mitigations such as Content Security Policy (CSP) and HTML sanitizers like DOMPurify.
☆130Feb 4, 2026Updated last week
Alternatives and similar repositories for GMSGadget
Users that are interested in GMSGadget are comparing it to the libraries listed below
Sorting:
- ☆31Jan 31, 2026Updated 2 weeks ago
- A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.☆769Dec 9, 2025Updated 2 months ago
- ☆48Aug 2, 2025Updated 6 months ago
- Easily create and share Proof of Concepts in HTML, JavaScript, etc. with custom headers, all via query parameters☆13Oct 1, 2025Updated 4 months ago
- A collection of client-side libraries with HTML injection vulnerabilities and DOM clobbering gadgets.☆48Aug 31, 2025Updated 5 months ago
- HTML Universal Identifier☆65Dec 15, 2024Updated last year
- A collection of Server-Side Prototype Pollution gadgets and exploits☆222Feb 6, 2025Updated last year
- Awesome MXSS ??☆56Sep 30, 2024Updated last year
- ☆123Dec 6, 2023Updated 2 years ago
- A collection of pyjails!☆27Dec 15, 2025Updated 2 months ago
- Useful configurations for the DomLogger++ extension☆48Sep 7, 2024Updated last year
- OAuch is an open-source security best practices and threats analyzer for OAuth 2.0 authorization server implementations☆12Sep 4, 2025Updated 5 months ago
- Clickme is a powerful multi-step clickjacking tool designed for security professionals. Create, visualize, and demonstrate complex clickj…☆14Sep 4, 2025Updated 5 months ago
- PP-finder Help you find gadget for prototype pollution exploitation☆190Aug 8, 2024Updated last year
- CookieFarm is a Attack/Defense CTF framework inspired by DestructiveFarm, developed by the Italian team ByteTheCookies. What sets CookieF…☆19Updated this week
- This is the data that powers the PortSwigger URL validation bypass cheat sheet.☆58Feb 5, 2026Updated last week
- CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scr…☆561Feb 7, 2026Updated last week
- ☆20Apr 10, 2025Updated 10 months ago
- ☆11May 16, 2024Updated last year
- Powershell Based tool for gathering information related to O365 intrusions and potential Breaches☆17Dec 29, 2024Updated last year
- A collection of js analysis tools & scripts.☆18Updated this week
- Differential testing framework for HTTP implementations☆923Jan 21, 2026Updated 3 weeks ago
- A fancier postMessage tracker with Chrome Manifest version V3 support and a few additional features, inspired by Frans Rosens postmessage…☆119Sep 12, 2025Updated 5 months ago
- Nuclei templates to run on urls☆17Sep 14, 2023Updated 2 years ago
- King-of-the-Hill game for the 2nd International Cybersecurity Challenge @ San Diego, California USA☆14Aug 9, 2023Updated 2 years ago
- Read & write JavaScript values from Python with the V8 serialization format.☆19Sep 30, 2025Updated 4 months ago
- Fast exfiltration of text using only CSS and Ligatures☆89Sep 3, 2025Updated 5 months ago
- Finds graphql queries in javascript files☆68May 18, 2024Updated last year
- CSPT is an open-source Burp Suite extension to find and exploit Client-Side Path Traversal.☆159Jul 2, 2024Updated last year
- A Discord Bot that announces your members' HTB solves.☆18Apr 19, 2024Updated last year
- ☆21Sep 12, 2025Updated 5 months ago
- This tool automates and facilitates an AES CBC BitFlip attack☆18Jan 17, 2024Updated 2 years ago
- ☆78Mar 26, 2024Updated last year
- Generates a `php://filter` chain that adds a prefix and a suffix to the contents of a file.☆234Oct 8, 2024Updated last year
- Python's library written in Rust to quickly factor `n = pq` when around >50% bits of `p` and `q` are known which are distributed at rando…☆19Jul 16, 2021Updated 4 years ago
- A CLI to exploit parameters vulnerable to PHP filter chain error based oracle.☆327Jun 2, 2024Updated last year
- ☆88Sep 20, 2024Updated last year
- Automated JavaScript Debugging Tool using CDP - Automatically sets breakpoints for specified strings/patterns in JavaScript code☆96Dec 22, 2024Updated last year
- My CTF challenges, especially cryptography☆25Mar 4, 2025Updated 11 months ago