Python tool that probes websites for open redirection via headers, JavaScript, and meta-tag refresh, pulls candidate URLs from the Wayback Machine, and checks CRLF injection and DOM XSS.
-
Updated
Sep 28, 2026 - Python
Python tool that probes websites for open redirection via headers, JavaScript, and meta-tag refresh, pulls candidate URLs from the Wayback Machine, and checks CRLF injection and DOM XSS.
OWASP Xenotix XSS Exploit Framework is an advanced Cross Site Scripting (XSS) vulnerability detection and exploitation framework.
XSSB is a proactive DOM sanitizer, defending against client-side injection attacks!
MIT license BRS-XSS is a modular Python CLI scanner for XSS vulnerabilities. Features context-aware payloads, WAF evasion, DOM analysis via Playwright, ML-based risk scoring, and export in HTML/JSON/SARIF. Designed for integration with Brabus Recon Suite (BRS).
Find sources and sinks in js code that could lead to DOM XSS 🔎💧🚰
Focused XSS fuzz scanner with smart payloads, reflection analysis, CSP checks, WAF hints, DOM sink detection, and optional browser validation.
xss-labs for learning web application security. Each lab demonstrates a different XSS vulnerability with interactive examples and solutions. Frontend-only, no server required.
DOM-based XSS flaw where location.search is injected into the page via innerHTML, letting us execute arbitrary JavaScript.
DOM-based XSS where location.search is written into the page via innerHTML, letting us inject HTML and trigger alert(1) using an SVG onload payload.
DOM XSS in jQuery anchor href attribute sink using location.search source
Discovering the JavaScript parameters for dom-xss
es-chromium: a Chromium build that tracks attacker-controlled data through V8 and Blink and reports DOM-XSS as a flow, not a guess. The browser agent behind EyalSec.
Intentionally vulnerable static website for testing DOM-based XSS detection tools, such as Dalfox. Educational and testing use only.
URDev’s Ultimate Injection Template is my personal payload collection: a comprehensive reference collection of web injection vectors, focused primarily on client-side execution surfaces in modern and legacy web applications.
A chrome extension to detect DOM changes and reflections to find XSS
Ultimate DOM Clobbering Cheat Sheet - 100+ exploitation vectors for XSS, CSP bypass, and client-side attacks. Covers browser compatibility, framework evasion, and real-world exploit chains for security researchers and bug bounty hunters
Advanced Cross-Site Scripting (XSS) vulnerability testing framework with WAF bypass, DOM XSS detection, and comprehensive reporting capabilities.
Intentionally vulnerable single-page dashboard demonstrating es-chromium DOM-XSS taint tracking - 21 flows across 8 sources and 18 sinks, each reachable from one URL. Demo target only.
An extension to find possible parameters in a web page DOM
To associate your repository with the dom-xss topic, visit your repo's landing page and select "manage topics."