
shadow-repeater
Burp Suite Repeater extension that automatically mutates payloads and analyzes responses to uncover path traversal, SQL injection, XSS, and other web…

Burp Suite Repeater extension that automatically mutates payloads and analyzes responses to uncover path traversal, SQL injection, XSS, and other web…

Request a Quote for WooCommerce (Addify) <= 2.9.2 Unauthenticated arbitrary file upload via afrfq_submit_quote_via_popup

Popup for CF7 with Sweet Alert <= 1.6.5 - Cross-Site Request Forgery

Exploit for CVE-2024-38856 affecting Apache OFBiz versions before 18.12.15

CVE-2026-56292 - AcyMailing for Joomla unauthenticated SQL injection scanner

Detects time-based SQL injection by sending crafted GET requests to multiple URLs and measuring delayed responses; includes cookie support for…

Burp extension scanner for CRLF injection and HTTP desync attacks, using mutated probes, WAF false-positive checks, and optional…

Web vulnerability scanner focused on automated XSS/CSP bypass payload testing and batch SQL injection detection, using SQLMap and reporting only…

CVE-2025-29927: Next.js Middleware Exploit

Share Buttons – Social Media <= 1.0.2 - Unauthenticated SQL Injection

SqlMap_BurpSuite

Adobe Experience Manager Childlist Selector - Cross-Site Scripting

CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

The Clickjacking Exploit Detector uses webpage scanning techniques to identify potential vulnerabilities and provide analysis of those elements.


Python-based web crawler and SQL injection vulnerability scanner using dork queries. Supports proxy and automated scanning for security testing.

CVE-2019-12460|Reflected XSS in WebPort-v1.19.1 impacts users who open a maliciously crafted link or third-party web page.

Non-intrusive checker for CVE-2026-63030 / CVE-2026-60137 ("wp2shell"), a pre-authentication RCE chain in WordPress core.