| Dumb0 | Outil de récupération de noms d'utilisateur | https://github.com/0verl0ad/Dumb0/ |
| CMSsc4n | Outil d'identification | https://github.com/n4xh4ck5/CMSsc4n |
| Puppet | Outil d'identification | https://github.com/Poil/puppet-websites-facts |
| pyfiscan | Outil d'identification | https://github.com/fgeek/pyfiscan |
| XAttacker | Outil d'exploitation | https://github.com/Moham3dRiahi/XAttacker |
| beecms | Outil d'exploitation | https://github.com/CHYbeta/cmsPoc |
| CMSXPL | Outil d'exploitation | https://github.com/tanprathan/CMS-XPL |
| JMassExploiter | Outil d'exploitation | https://github.com/anarcoder/JoomlaMassExploiter |
| WPMassExploiter | Outil d'exploitation | https://github.com/anarcoder/WordPressMassExploiter |
| CMSExpFram | Outil d'exploitation | https://github.com/Q2h1Cg/CMS-Exploit-Framework |
| LotusXploit | Outil d'exploitation | https://github.com/Hood3dRob1n/LotusCMS-Exploit |
| BadMod | Outil d'exploitation | https://github.com/MrSqar-Ye/BadMod |
| M0B | Outil d'exploitation | https://github.com/mobrine-mob/M0B-tool |
| LetMeFuckIt | Outil d'exploitation | https://github.com/onthefrontline/LetMeFuckIt-Scanner |
| magescan | Outil d'exploitation | https://github.com/steverobbins/magescan |
| PRESTA | Outil d'exploitation | https://github.com/AlisamTechnology/PRESTA-modules-shell-exploit |
| EktronE | Outil d'exploitation | https://github.com/tomkallo/Ektron_CMS_8.02_exploit |
| XBruteForcer | Outil de brute force | https://github.com/Moham3dRiahi/XBruteForcer |
| CoMisSion | Outil d'analyse | https://github.com/Intrinsec/comission |
| droopescan | Outil d'analyse | https://github.com/droope/droopescan |
| CMSmap | Outil d'analyse | https://github.com/Dionach/CMSmap |
| JoomScan | Outil d'analyse | https://github.com/rezasp/joomscan |
| VBScan | Outil d'analyse | https://github.com/rezasp/vbscan |
| JoomlaScan | Outil d'analyse | https://github.com/drego85/JoomlaScan |
| c5scan | Outil d'analyse | https://github.com/auraltension/c5scan |
| T3scan | Outil d'analyse | https://github.com/Oblady/T3Scan |
| moodlescan | Outil d'analyse | https://github.com/inc0d3/moodlescan |
| SPIPScan | Outil d'analyse | https://github.com/PaulSec/SPIPScan |
| WPHunter | Outil d'analyse | https://github.com/aryanrtm/WP-Hunter |
| WPSeku | Outil d'analyse | https://github.com/m4ll0k/WPSeku |
| ACDrupal | Outil d'analyse | https://github.com/mrmtwoj/ac-drupal |
| Plown | Outil d'analyse | https://github.com/unweb/plown |
| conscan | Outil d'analyse | https://github.com/nullsecuritynet/tools/tree/master/scanner/conscan |
| CMSScanner | Outil d'analyse | https://github.com/CMS-Garden/cmsscanner |
| cmsExplorer | Outil d'analyse | https://code.google.com/archive/p/cms-explorer |
| WPScan | Outil d'analyse | https://github.com/wpscanteam/wpscan |
| MooScan | Outil d'analyse | https://github.com/vortexau/mooscan |
| Scanners | Outil d'analyse | https://github.com/b3o1/Scanners |
| LiferayScan | Outil d'analyse | https://github.com/bcoles/LiferayScan |
| InfoLeak | Outil d'analyse | https://github.com/SIWECOS/InfoLeak-Scanner |
| joomlavs | Outil d'analyse | https://github.com/rastating/joomlavs |
| WAScan | Outil d'analyse | https://github.com/m4ll0k/WAScan |
| RedHawk | Outil d'analyse | https://github.com/Tuhinshubhra/RED_HAWK |
| HostileSBF | Outil d'analyse | https://github.com/nahamsec/HostileSubBruteforcer |