Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
webhacklist — Archive of the Top 10 Web Hacking Techniques - every nominee since 2006, preserved | Kitploit
Tools/GitHubGitHub/irsdl/webhacklist
Vulnerability AnalysisInformation GatheringWeb SecurityDigital ForensicsPapers & ResearchLearning & EducationCurated Resources
GitHubirsdl/webhacklist

webhacklist

Archive of the Top 10 Web Hacking Techniques - every nominee since 2006, preserved

View Repository
847134151 day agoReviewed by Kitploit
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Top 10 Web Hacking Techniques — the complete archive, 2006 → 2025



Live archive GitHub stars GitHub forks Last commit PRs welcome Sponsor

The complete archive of the Top 10 Web Hacking Techniques — every nominated technique (not just the winners) for every year since 2006, plus PDF snapshots of the original announcement posts so the record survives its hosts.

🌐 Read it online at webhacklist.com

Search every technique, filter by year, and open any preserved document without leaving the browser.

Browse by year · Where things are · File layout · The three eras · The PDF archive · Face the Judge · Support · Contributing


🔎 What is this?

Every year since 2006, the web security community has nominated the most innovative web hacking research, voted, and crowned a Top 10. The list was started by Jeremiah Grossman and is continued today by James Kettle at PortSwigger.

The annual announcement posts, however, have a habit of disappearing — WhiteHat Security's blog (home of the 2011–2015 lists) is already gone. This repository keeps the whole thing in one durable, greppable place:

  • One Markdown file per year with every nominated technique — all 1,136 of them, plus 423 later audit finds the nomination rounds missed, for 1,559 techniques spanning two decades of web security research.
  • PDF snapshots of the original nominee and winner announcement pages, captured with reproducible tooling and recorded provenance.

[!IMPORTANT] The year lists are complete: everything that was officially nominated is in. That said, the nomination rounds occasionally missed notable research. If you know of work that should have been on a year's list, open an issue or PR — anything that qualifies as a web hacking technique nominee for that year will be reviewed and, if it fits, added to its relevant year. Later audit additions are visibly separated from the original nominations, require a full private evaluation under the judging skill’s current merit criteria, and record Added / Not added under ai-evaluation/.

[!TIP] Many of the older links have died. Paste any dead URL into the Wayback Machine — most are preserved there, and the PDF archive preserves the announcement pages themselves.

🗺️ Where things are

webhacklist/
├── 2006.md … 2025.md         ← the lists — every nominated technique, one file per year
├── <year>-ai.md              ← AI-collected candidates for a year with no vote yet — machine-assembled, unreviewed, kept deliberately separate from the curated lists above
├── ai-evaluation/<year>/     ← candidate links, Added / Not added, and decision history
├── original-listings/        ← PDF snapshots of the original announcement posts
│   ├── <year>-nominees.pdf   ←   the full nominee list for that year
│   ├── <year>-top10.pdf      ←   the post naming the winning ten
│   └── README.md             ←   per-year index, notes, and archive rationale
├── website/                   ← production progressive archive website
│   ├── archive-years.json     ←   publishing registry
│   └── data/                  ←   generated small catalogue + one JSON shard per collection
├── tools/                    ← the capture pipeline that builds the PDF archive
│   ├── capture_pdf.py        ←   headless-Chrome capture driver + verifier
│   ├── sources.json          ←   manifest: what to capture, from where, with assertions
│   └── capture-report.json   ←   provenance log of the last run
└── assets/                   ← logo and artwork

📖 How each year file is laid out

Every <year>.md opens with a ## Top 10 section holding the ten techniques that actually won that year's vote, in finishing order, each tagged with its rank:

## Top 10

-   [Blind SSTI](https://github.com/vladko312/Research_Successful_Errors) **#1**
-   [ORM Leaking More Than You Joined For](https://www.elttam.com/blog/leaking-more-than-you-joined-for/) **#2**

Every year file uses that one layout: one - bullet per technique, no trailing backslashes and no blank lines inside the lists.

Everything else nominated that year follows under ## Other nominations, unranked and in its original order. So you can read the ten that stood out without losing the long tail — which is often where the genuinely novel work hides.

[!NOTE] Ranks come from the announcement posts, but the entry text stays as the nominee list had it. A winner's title in the results post is sometimes shorter or worded differently from its nomination, so the two don't always read identically.

Research that was held out of the vote

In four years the organisers kept some research out of the competition to avoid a conflict of interest. Rather than let it vanish, those entries sit at the top of ## Other nominations, each tagged with the stage it was held out of — the stages differed, so the wording does too — under a note explaining what happened:

YearHeld outWhy
2016/17Cracking the Lens; XSS without HTMLPortSwigger research was excluded up front; by the time a recusal system replaced that rule it was too late to reintroduce it, so it never even reached the nominee list
2019HTTP Desync AttacksWon the community vote outright, but James Kettle declined to rank his own research first
2024Gotta cache 'em all; Splitting the email atom; Listen to the whispersAll three reached the final fifteen and were then held out of the panel vote
2025HTTP/1.1 must dieReached the final fifteen, held out of the panel's top ten

Every other year the organisers state that their own research competed normally — in 2020 PortSwigger's Portable Data exFiltration placed 2nd, and in 2021 HTTP/2: The Sequel is Always Worse placed 2nd — so nothing is missing from those.

📅 Browse by year

Each year links to its curated list. Nominated counts the techniques that went into that year's official round — the community nominated far more than ten per year. Audit counts the research that round missed, recovered later and kept visibly separate under ## Missed from the original list.

Download Tool