
GraphQLGrapper
Burp Suite extension to extract and collect GraphQL API endpoints from HTTP request history for security testing and reconnaissance.

Burp Suite extension to extract and collect GraphQL API endpoints from HTTP request history for security testing and reconnaissance.

A Burp Suite extension that integrates Dalfox XSS scanner directly into your workflow.

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

Import To Sitemap is a Burp Suite Extension to import wstalker CSV file or ZAP export file into Burp Sitemap

Burp Suite extension that auto-replaces cookies and headers in requests using configurable rules. Eliminates manual copy-pasting of session tokens…

Burp Suite extension for detecting CVE-2025-55182 (React2Shell) unsafe deserialization vulnerability. Features safe digest check, PoC redirect mode,…

Burp Suite extension to detect CVE-2025-14847 (MongoBleed) via manual leak tests from a dedicated UI tab.

Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324

Burp Suite extension exploiting CVE-2014-9301 in Alfresco Referer Proxy for targeted web application penetration testing.

Burp Suite extension for detecting and testing CVE-2024-34102, a critical web vulnerability, enabling automated security assessment and exploitation…

Burp Suite extension for automated detection and exploitation of HTTP request smuggling vulnerabilities, supporting HTTP/1.1 and HTTP/2-downgrade…

The new bridge between Burp Suite and Frida!

Burp plugin able to find reflected XSS on page in real-time while browsing on site

Advanced Burp Suite Logging Extension

Pcap importer for Burp

A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzing


Burp Active Scan extension to identify Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046