
Archive of the Top 10 Web Hacking Techniques - every nominee since 2006, preserved
The complete archive of the Top 10 Web Hacking Techniques — every nominated technique (not just the winners) for every year since 2006, plus PDF snapshots of the original announcement posts so the record survives its hosts.
Search every technique, filter by year, and open any preserved document without leaving the browser.
Browse by year · Where things are · File layout · The three eras · The PDF archive · Face the Judge · Support · Contributing
Every year since 2006, the web security community has nominated the most innovative web hacking research, voted, and crowned a Top 10. The list was started by Jeremiah Grossman and is continued today by James Kettle at PortSwigger.
The annual announcement posts, however, have a habit of disappearing — WhiteHat Security's blog (home of the 2011–2015 lists) is already gone. This repository keeps the whole thing in one durable, greppable place:
[!IMPORTANT] The year lists are complete: everything that was officially nominated is in. That said, the nomination rounds occasionally missed notable research. If you know of work that should have been on a year's list, open an issue or PR — anything that qualifies as a web hacking technique nominee for that year will be reviewed and, if it fits, added to its relevant year. Later audit additions are visibly separated from the original nominations, require a full private evaluation under the judging skill’s current merit criteria, and record Added / Not added under
ai-evaluation/.
[!TIP] Many of the older links have died. Paste any dead URL into the Wayback Machine — most are preserved there, and the PDF archive preserves the announcement pages themselves.
webhacklist/
├── 2006.md … 2025.md ← the lists — every nominated technique, one file per year
├── <year>-ai.md ← AI-collected candidates for a year with no vote yet — machine-assembled, unreviewed, kept deliberately separate from the curated lists above
├── ai-evaluation/<year>/ ← candidate links, Added / Not added, and decision history
├── original-listings/ ← PDF snapshots of the original announcement posts
│ ├── <year>-nominees.pdf ← the full nominee list for that year
│ ├── <year>-top10.pdf ← the post naming the winning ten
│ └── README.md ← per-year index, notes, and archive rationale
├── website/ ← production progressive archive website
│ ├── archive-years.json ← publishing registry
│ └── data/ ← generated small catalogue + one JSON shard per collection
├── tools/ ← the capture pipeline that builds the PDF archive
│ ├── capture_pdf.py ← headless-Chrome capture driver + verifier
│ ├── sources.json ← manifest: what to capture, from where, with assertions
│ └── capture-report.json ← provenance log of the last run
└── assets/ ← logo and artwork
Every <year>.md opens with a ## Top 10 section holding the ten techniques that
actually won that year's vote, in finishing order, each tagged with its rank:
## Top 10
- [Blind SSTI](https://github.com/vladko312/Research_Successful_Errors) **#1**
- [ORM Leaking More Than You Joined For](https://www.elttam.com/blog/leaking-more-than-you-joined-for/) **#2**
Every year file uses that one layout: one - bullet per technique, no trailing
backslashes and no blank lines inside the lists.
Everything else nominated that year follows under ## Other nominations, unranked
and in its original order. So you can read the ten that stood out without losing the
long tail — which is often where the genuinely novel work hides.
[!NOTE] Ranks come from the announcement posts, but the entry text stays as the nominee list had it. A winner's title in the results post is sometimes shorter or worded differently from its nomination, so the two don't always read identically.
In four years the organisers kept some research out of the competition to avoid a
conflict of interest. Rather than let it vanish, those entries sit at the top of
## Other nominations, each tagged with the stage it was held out of — the stages
differed, so the wording does too — under a note explaining what happened:
| Year | Held out | Why |
|---|---|---|
| 2016/17 | Cracking the Lens; XSS without HTML | PortSwigger research was excluded up front; by the time a recusal system replaced that rule it was too late to reintroduce it, so it never even reached the nominee list |
| 2019 | HTTP Desync Attacks | Won the community vote outright, but James Kettle declined to rank his own research first |
| 2024 | Gotta cache 'em all; Splitting the email atom; Listen to the whispers | All three reached the final fifteen and were then held out of the panel vote |
| 2025 | HTTP/1.1 must die | Reached the final fifteen, held out of the panel's top ten |
Every other year the organisers state that their own research competed normally — in 2020 PortSwigger's Portable Data exFiltration placed 2nd, and in 2021 HTTP/2: The Sequel is Always Worse placed 2nd — so nothing is missing from those.
Each year links to its curated list. Nominated counts the techniques that went into
that year's official round — the community nominated far more than ten per year.
Audit counts the research that round missed, recovered later and kept visibly
separate under ## Missed from the original list.