
wp2shell-Exploit-Waf-Bypass
WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

Burp Plugin to Bypass WAFs through the insertion of Junk Data

A next-generation HTTP stealth proxy which perfectly cloaks requests as the Chrome browser across all layers of the stack.

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

A cheat sheet that contains advanced queries for SQL Injection of all types.

woodpecker-plugins

A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques

Like curl, but it gets past Anubis and Cloudflare bot-walls.

xpath is a fast, multi-technique XPath injection scanner written in Nim. It focuses on practical detection, response comparison, visible extraction,…

WordPress HTMega Unauthenticated PII Disclosure Exploit (CVE-2026-4106)

Stuff that doesn't deserves its own repository.

WebPwn3r - Web Applications Security Scanner.

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

Successor of Undetected-Chromedriver. Providing a blazing fast framework for web automation, webscraping, bots and any other creative ideas which are…

Undetected version of the Playwright testing and automation library.

CVE-2025-25369