
nowafpls
Burp Plugin to Bypass WAFs through the insertion of Junk Data

Burp Plugin to Bypass WAFs through the insertion of Junk Data

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).



ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

A new way to exploit CVE-2025-58360 bypass WAF

This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware…

Demonstration on exploitation on Drupal 7.57 (CVE-2018-7600) with and without WAF(Web Application Firewall)

CVE-2025-55182-bypass-waf


🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

Tests your WAF with +160 payloads

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

POC for CVE-2024-34102 : Unauthenticated Magento XXE and bypassing WAF , You will get http connection on ur webhook
