
yLog4j
PortSwigger Burp Plugin for the Log4j (CVE-2021-44228)

PortSwigger Burp Plugin for the Log4j (CVE-2021-44228)

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Discover hidden parameters in Caido

A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

A Burp Extender plugin, that will make binary soap objects readable and modifiable.

HopLa Burp Suite Extender plugin - Brings AI capabilities, autocompletion support, and a set of useful payloads to Burp Suite

A fast WordPress plugin enumeration tool

Jenkins plugin for automated mobile app testing via Perfecto cloud, managing secure tunnel connections and app uploads within CI/CD pipelines.

Spring4Shell , Spring Framework RCE (CVE-2022-22965) , Burpsuite Plugin

he Hunk Companion Plugin for WordPress: Vulnerable to Unauthorized Plugin Installation/Activation (Versions Up to and Including 1.8.4)

Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation

Zita Site Builder <= 1.0.2 - Missing Authorization to Arbitrary Plugin Installation

Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

Proof-of-concept exploit for CVE-2025-6792 demonstrating unauthorized Pusher channel subscription and event eavesdropping in a WordPress plugin via…

SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.

Burp Plugin to decrypt AES encrypted traffic on the fly

Burp Suite plugin for automated token extraction and replacement in HTTP requests, supporting JSON, XML, cookies, and URL parameters to streamline…