
Wildfire
CVE-2026-39154, Stored XSS in CometChat JS SDK

CVE-2026-39154, Stored XSS in CometChat JS SDK
A simple Burp Suite extension to crawl JavaScript (JS) files in passive mode and display the results directly on the issues

A standalone Blind XSS Script.

Extracts dynamically loaded JavaScript files by statically analyzing website HTML and JS, detecting webpack chunks, import() lazy loading, and source…

「🔑」A tool used to hunt down API key leaks in JS files and pages

Extracts all possible endpoints, URLs, and paths from JavaScript files using customizable regex patterns for web application reconnaissance and API…

Haraj Script 3.7 - Authenticated Stored XSS

Automated Python scanner to detect hardcoded secrets (Private Keys, API Tokens) in client-side JavaScript files.

POC for PDF JS' CVE-2024-4367 vuln

Regular expression matching for URL's. Maintained, safe, and browser-friendly version of url-regex. Resolves CVE-2020-7661 for Node.js servers.

A powerfull websites compiler/obfuscator for optimization or intellectual property protection purposes.

"qs" prototype poisoning vulnerability ( CVE-2022-24999 )

Scans websites and JS files for exposed Gemini API keys, verifies them live, enumerates accessible services, and provides a browser client for direct…

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

Get information client with getdatareport (Plugin)

PoC Exploit CVE-2018-6389

AI-powered skill router pack for reverse engineering, penetration testing, and security research. Routes AI agents to correct methodologies and…

Modular web application reconnaissance framework for automated subdomain enumeration, directory brute-forcing, and extraction of endpoints, JS URLs,…