
CVE-2026-21876
Minimal PoC and Docker container demonstrating a WAF bypass in OWASP ModSecurity CRS via multipart charset handling, leading to XSS payload delivery.

Minimal PoC and Docker container demonstrating a WAF bypass in OWASP ModSecurity CRS via multipart charset handling, leading to XSS payload delivery.

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques

Python-based detector for FortiWeb authentication bypass (CVE-2025-xxxxx). Sends exploit payload to create a test user as proof of exploitation.

Demonstrates CVE-2022-31813 Apache HTTP Server bypass using X-Real-IP header manipulation to evade access controls, with a Docker-based test…

A new way to exploit CVE-2025-58360 bypass WAF

CVE-2021-44228

CVE-2025-55182-bypass-waf

Proof-of-concept exploit for CVE-2020-6519, a Content Security Policy bypass vulnerability in Chromium 83, enabling full CSP bypass across platforms.

pentest on MagnoHost hosting provider & MeteorCloud infrastructure with 15+ servers mapped. Findings: MariaDB exposed on 6 servers, OmniDialer…

🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Proof-of-concept for CVE-2024-34102 exploiting unauthenticated Magento XXE and WAF bypass by sending a crafted request to the…

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.