
toxssin
An XSS exploitation command-line interface and payload generator.

An XSS exploitation command-line interface and payload generator.

ISeeYou is a Bash and Javascript tool to find the exact location of the users during social engineering or phishing engagements. Using exact location…

JShell - Get a JavaScript shell with XSS.

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

Proof-of-concept exploit for XSS vulnerability in Jamovi <=1.6.18. Demonstrates crafting malicious .omv documents with JavaScript payloads to achieve…

CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the…

Proof-of-concept exploit for CVE-2025-26788 demonstrating WebAuthn credential ID manipulation via JavaScript hooking to bypass authentication in…

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

Payload Generation Framework

All-in-One WP Migration < 7.63 - Unauthenticated Reflected XSS + CSRF