This repository contains wordlists for each versions of common web applications and content management systems (CMS). Each version contains a wordlist of all the files directories for this version.
☆535Dec 4, 2024Updated last year
Alternatives and similar repositories for webapp-wordlists
Users that are interested in webapp-wordlists are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Python script to check if there is any differences in responses of an application when the request comes from a search engine's crawler.☆25Oct 1, 2023Updated 2 years ago
- Rockyou for web fuzzing☆3,108Mar 11, 2026Updated 3 weeks ago
- Awesome list of step by step techniques to achieve Remote Code Execution on various apps!☆1,944Oct 7, 2023Updated 2 years ago
- A script to factorize integers with sagemath and factordb.☆12Feb 11, 2025Updated last year
- A webshell plugin and interactive shell for pentesting JoGet application.☆14May 19, 2022Updated 3 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting with the flexibility to host WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Cloudways by DigitalOcean.
- A collection of http fuzzing python scripts to fuzz HTTP servers for bugs.☆16Oct 1, 2023Updated 2 years ago
- bypass-url-parser☆1,123Mar 28, 2026Updated last week
- A repository that includes all the important wordlists used while bug hunting.☆1,395Mar 11, 2023Updated 3 years ago
- S3 Recon tips and tricks collected from different resources,Sorry if i missed to mention all resources owners☆27Nov 13, 2021Updated 4 years ago
- De-clutter a list of URLs☆386Mar 8, 2026Updated last month
- ☆755Jun 26, 2024Updated last year
- declutters url lists for crawling/pentesting☆1,543Feb 23, 2025Updated last year
- Decode the values of common Windows properties such as userAccountControl and sAMAccountType.☆25Oct 2, 2023Updated 2 years ago
- A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file.☆14May 3, 2022Updated 3 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click and start building anything your business needs.
- A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets☆1,538Mar 8, 2026Updated last month
- A python script to check if URLs are allowed or disallowed by a robots.txt file.☆23Feb 11, 2025Updated last year
- A script to enumerate valid usernames based on the requests response times.☆23May 3, 2022Updated 3 years ago
- This Python script can be used to bypass IP source restrictions using HTTP headers.☆400Sep 16, 2025Updated 6 months ago
- Automatically extracts NT and LM hashes from Windows memory dumps based on volatility.☆27Oct 1, 2023Updated 2 years ago
- Hidden parameters discovery suite☆224Nov 14, 2022Updated 3 years ago
- Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one pl…☆1,037Aug 23, 2025Updated 7 months ago
- Fast and customizable vulnerability scanner For JIRA written in Python☆344Dec 31, 2024Updated last year
- Free, libre, effective, and data-driven wordlists for all!☆647Sep 10, 2021Updated 4 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Real-world infosec wordlists, updated regularly☆1,732Updated this week
- Useful "Match and Replace" burpsuite rules☆367Sep 26, 2023Updated 2 years ago
- Generate tens of thousands of subdomain combinations in a matter of seconds☆274Sep 25, 2023Updated 2 years ago
- 🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast…☆1,570Mar 16, 2026Updated 3 weeks ago
- ☆32Dec 30, 2022Updated 3 years ago
- A python script to automatically add a KeyCredentialLink to newly created users, by quickly connecting to them with default credentials.☆27Mar 17, 2024Updated 2 years ago
- Hidden parameters discovery suite☆2,039Sep 8, 2024Updated last year
- Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X!☆2,576Mar 8, 2026Updated last month
- Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist☆1,504Jan 8, 2026Updated 3 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- A python script to scan for Apache Tomcat server vulnerabilities.☆890Jan 12, 2026Updated 2 months ago
- MailMasta wordpress plugin Local File Inclusion vulnerability (CVE-2016-10956)☆20May 3, 2022Updated 3 years ago
- Nuclei plugin for BurpSuite☆1,325Oct 22, 2025Updated 5 months ago
- This includes all the templates of nuclei collected from different sources☆18Dec 30, 2022Updated 3 years ago
- A simple python script to dump remote files through a local file read or local file inclusion web vulnerability.☆78Mar 16, 2024Updated 2 years ago
- Gotator is a tool to generate DNS wordlists through permutations.☆511Jul 17, 2022Updated 3 years ago
- It grep subdomains, email/username, build custom wordlist etc from gau results☆50Nov 4, 2022Updated 3 years ago