1
0
mirror of https://github.com/swisskyrepo/PayloadsAllTheThings.git synced 2025-04-03 21:19:05 +02:00
A list of useful payloads and bypass for Web Application Security and Pentest/CTF https://github.com/swisskyrepo/PayloadsAllTheThings
Go to file
2025-04-01 20:22:10 +02:00
_LEARNING_AND_SOCIALS Markdown Linting - Source Code, JWT, RMI, LDAP, LaTeX 2025-03-26 16:48:22 +01:00
_template_vuln Update _template_vuln page 2024-11-13 13:39:19 +01:00
.github Markdown Linting - Improving rules 2025-03-26 22:51:26 +01:00
Account Takeover Fix markdown style issues in Account Takeover 2024-11-13 15:30:33 +01:00
API Key Leaks Markdown Linting - API, Business Logic, Clickjacking 2025-03-24 16:16:58 +01:00
Business Logic Errors Markdown Linting - API, Business Logic, Clickjacking 2025-03-24 16:16:58 +01:00
Clickjacking Markdown Linting - API, Business Logic, Clickjacking 2025-03-24 16:16:58 +01:00
Client Side Path Traversal Markdown Linting - CORS, CRLF, CSPT, CSRF, Command Injection 2025-03-24 16:52:42 +01:00
Command Injection Markdown Linting - CORS, CRLF, CSPT, CSRF, Command Injection 2025-03-24 16:52:42 +01:00
CORS Misconfiguration Markdown Linting - CORS, CRLF, CSPT, CSRF, Command Injection 2025-03-24 16:52:42 +01:00
CRLF Injection Markdown Linting - CORS, CRLF, CSPT, CSRF, Command Injection 2025-03-24 16:52:42 +01:00
Cross-Site Request Forgery Markdown Linting - CORS, CRLF, CSPT, CSRF, Command Injection 2025-03-24 16:52:42 +01:00
CSV Injection Markdown Linting - CSV, CVE, DBS, LFI, GWT, GraphQL 2025-03-26 16:22:53 +01:00
CVE Exploits Markdown Linting - CSV, CVE, DBS, LFI, GWT, GraphQL 2025-03-26 16:22:53 +01:00
Denial of Service XXE - Fix typo 2025-03-17 17:02:00 +01:00
Dependency Confusion Markdown Linting - CSV, CVE, DBS, LFI, GWT, GraphQL 2025-03-26 16:22:53 +01:00
Directory Traversal Markdown Linting - CSV, CVE, DBS, LFI, GWT, GraphQL 2025-03-26 16:22:53 +01:00
DNS Rebinding Markdown Linting - CSV, CVE, DBS, LFI, GWT, GraphQL 2025-03-26 16:22:53 +01:00
DOM Clobbering Markdown Linting - CSV, CVE, DBS, LFI, GWT, GraphQL 2025-03-26 16:22:53 +01:00
External Variable Modification External Variable Modification 2025-03-07 12:15:00 +01:00
File Inclusion Fix broken links 2025-03-27 11:16:36 +01:00
Google Web Toolkit Markdown Linting - CSV, CVE, DBS, LFI, GWT, GraphQL 2025-03-26 16:22:53 +01:00
GraphQL Injection Markdown Linting - CSV, CVE, DBS, LFI, GWT, GraphQL 2025-03-26 16:22:53 +01:00
Headless Browser Markdown Linting - Parameters, Browsers, Deserialization Randomness 2025-03-26 16:33:07 +01:00
Hidden Parameters Markdown Linting - Parameters, Browsers, Deserialization Randomness 2025-03-26 16:33:07 +01:00
HTTP Parameter Pollution Markdown Linting - Parameters, Browsers, Deserialization Randomness 2025-03-26 16:33:07 +01:00
Insecure Deserialization Fix broken links 2025-03-27 11:16:36 +01:00
Insecure Direct Object References Markdown Linting - Parameters, Browsers, Deserialization Randomness 2025-03-26 16:33:07 +01:00
Insecure Management Interface Markdown Linting - Parameters, Browsers, Deserialization Randomness 2025-03-26 16:33:07 +01:00
Insecure Randomness Markdown Linting - Parameters, Browsers, Deserialization Randomness 2025-03-26 16:33:07 +01:00
Insecure Source Code Management Markdown Linting - Source Code, JWT, RMI, LDAP, LaTeX 2025-03-26 16:48:22 +01:00
Java RMI Markdown Linting - Source Code, JWT, RMI, LDAP, LaTeX 2025-03-26 16:48:22 +01:00
JSON Web Token Markdown Linting - Source Code, JWT, RMI, LDAP, LaTeX 2025-03-26 16:48:22 +01:00
LaTeX Injection Markdown Linting - Source Code, JWT, RMI, LDAP, LaTeX 2025-03-26 16:48:22 +01:00
LDAP Injection Markdown Linting - Source Code, JWT, RMI, LDAP, LaTeX 2025-03-26 16:48:22 +01:00
Mass Assignment Markdown Linting - Mass Assignment, NoSQL, OAuth, Redirect 2025-03-26 17:06:01 +01:00
Methodology and Resources Markdown Linting - Methodology 2025-03-24 16:00:54 +01:00
NoSQL Injection NoSQL injection WAF 2025-04-01 20:22:10 +02:00
OAuth Misconfiguration Markdown Linting - Mass Assignment, NoSQL, OAuth, Redirect 2025-03-26 17:06:01 +01:00
Open Redirect Markdown Linting - Mass Assignment, NoSQL, OAuth, Redirect 2025-03-26 17:06:01 +01:00
ORM Leak Markdown Linting - Mass Assignment, NoSQL, OAuth, Redirect 2025-03-26 17:06:01 +01:00
Prompt Injection Prompt Injection Update 2025-03-17 19:50:19 +01:00
Prototype Pollution Markdown Linting - Mass Assignment, NoSQL, OAuth, Redirect 2025-03-26 17:06:01 +01:00
Race Condition Markdown Linting - Mass Assignment, NoSQL, OAuth, Redirect 2025-03-26 17:06:01 +01:00
Regular Expression Markdown Linting - Mass Assignment, NoSQL, OAuth, Redirect 2025-03-26 17:06:01 +01:00
Request Smuggling Markdown Linting - SSI, SSRF, SSTI 2025-03-26 17:49:42 +01:00
SAML Injection Markdown Linting - SSI, SSRF, SSTI 2025-03-26 17:49:42 +01:00
Server Side Include Injection Markdown Linting - SSI, SSRF, SSTI 2025-03-26 17:49:42 +01:00
Server Side Request Forgery Markdown Linting - SSI, SSRF, SSTI 2025-03-26 17:49:42 +01:00
Server Side Template Injection Fix typo 2 2025-03-27 11:24:46 +01:00
SQL Injection Markdown Linting - SQL, Juggling, XSLT, XSS, Zip 2025-03-26 20:53:03 +01:00
Tabnabbing Markdown Linting - SQL, Juggling, XSLT, XSS, Zip 2025-03-26 20:53:03 +01:00
Type Juggling Markdown Linting - SQL, Juggling, XSLT, XSS, Zip 2025-03-26 20:53:03 +01:00
Upload Insecure Files Markdown Linting - SQL, Juggling, XSLT, XSS, Zip 2025-03-26 20:53:03 +01:00
Web Cache Deception Markdown Linting - SQL, Juggling, XSLT, XSS, Zip 2025-03-26 20:53:03 +01:00
Web Sockets Markdown Linting - SQL, Juggling, XSLT, XSS, Zip 2025-03-26 20:53:03 +01:00
XPATH Injection Markdown Linting - SQL, Juggling, XSLT, XSS, Zip 2025-03-26 20:53:03 +01:00
XSLT Injection Markdown Linting - SQL, Juggling, XSLT, XSS, Zip 2025-03-26 20:53:03 +01:00
XSS Injection Markdown Linting - SQL, Juggling, XSLT, XSS, Zip 2025-03-26 20:53:03 +01:00
XXE Injection XXE - Fix typo 2025-03-17 17:02:00 +01:00
Zip Slip Markdown Linting - SQL, Juggling, XSLT, XSS, Zip 2025-03-26 20:53:03 +01:00
.gitignore YAML Deserialization 2022-09-16 16:37:40 +02:00
CONTRIBUTING.md Fix broken links 2025-03-27 11:16:36 +01:00
custom.css CSS - Update style color + Blind SQL Oracle 2023-12-10 13:27:21 +01:00
DISCLAIMER.md Markdown Linting - Methodology 2025-03-24 16:00:54 +01:00
LICENSE Create License 2019-05-25 16:27:35 +02:00
mkdocs.yml SSTI references updates 2024-11-03 20:54:01 +01:00
README.md Markdown Linting - Methodology 2025-03-24 16:00:54 +01:00

Payloads All The Things

A list of useful payloads and bypasses for Web Application Security. Feel free to improve with your payloads and techniques ! I ❤️ pull requests :)

You can also contribute with a 🍻 IRL, or using the sponsor button

Sponsor Tweet

An alternative display version is available at PayloadsAllTheThingsWeb.

banner

📖 Documentation

Every section contains the following files, you can use the _template_vuln folder to create a new chapter:

  • README.md - vulnerability description and how to exploit it, including several payloads
  • Intruder - a set of files to give to Burp Intruder
  • Images - pictures for the README.md
  • Files - some files referenced in the README.md

You might also like the other projects from the AllTheThings family :

You want more ? Check the Books and Youtube channel selections.

🧑‍💻 Contributions

Be sure to read CONTRIBUTING.md

sponsors-list

Thanks again for your contribution! ❤️

🍻 Sponsors

This project is proudly sponsored by these companies:

sponsor-vaadata sponsor-projectdiscovery