
CVE-2021-26700
Proof-of-concept for CVE-2021-26700: remote code execution in the VSCode npm-script extension via malicious workspace settings.json, with detailed…

Proof-of-concept for CVE-2021-26700: remote code execution in the VSCode npm-script extension via malicious workspace settings.json, with detailed…

BurpSuite extension that converts HTTP requests into JavaScript XMLHttpRequest code for streamlined XSS proof-of-concept generation and web…

A Burp Extension to test applications for vulnerability to the Web Cache Deception attack

A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or LFI.

Burp plugin able to find reflected XSS on page in real-time while browsing on site

Burp Suite extension for extracting metadata from files

Burp extension to filter JSON on the fly with JQ queries in the HTTP message viewer.

Remote code execution in Mediawiki Score

ZIP File Raider - Burp Extension for ZIP File Payload Testing

Framework for identifying and exploiting out-of-band (OOB) application vulnerabilities with a custom DNS/token server, Burp Suite extension, and…

Proof of concept for CVE-2017-6640 as burp extension

Burp Suite extension to track vulnerability assessment progress

Demonstrates a local code execution exploit for Foxit PDF Reader via XFA-based PDFs, with step-by-step attack reproduction and extension to related…

Exploit for XSS via BBCode on Kunena extension before 5.1.14 for Joomla!

(Wordpress) Ninja Forms File Uploads Extension <= 3.0.22 – Unauthenticated Arbitrary File Upload

A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques

A Burp Extension designed to identify argument injection vulnerabilities.

Extension adds a new tab in Burp Suite called Extractor