📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: Cross-Site-Scripting
👤 项目作者: princemhzn007-ui
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 09:55:00

📝 项目描述:
A web security project focused on identifying and mitigating Cross-Site Scripting (XSS) vulnerabilities using secure coding practices, input validation, output encoding, and safe DOM manipulation.

🔗 点击访问项目地址 GitHub - princemhzn007-ui/Cross-Site-Scripting: A web security project focused on identifying and mitigating Cross-Site Scripting…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: xss-csp-lab
👤 项目作者: emmanuellawoniowei
🛠 开发语言: CSS
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 14:20:58

📝 项目描述:
Hands-on web security lab demonstrating Reflected, Stored & DOM-Based XSS, CSP protection, vulnerabilities, and mitigation techniques using PHP, JavaScript & CSS.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected #DOM

📦 项目名称: xssrecon
👤 项目作者: rix4uni
🛠 开发语言: Go
Star数量: 54 | 🍴 Fork数量: 11
📅 更新时间: 2026-08-11 04:42:38

📝 项目描述:
XSSRecon automates the process of testing URL parameters for reflection of a test payload rix4uni and further checks how special characters are handled (allowed, blocked, or converted).

🔗 点击访问项目地址 GitHub - rix4uni/xssrecon: XSSRecon automates the process of testing URL parameters for reflection of a test payload rix4uni and…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: devtalks-xss
👤 项目作者: orfloresti
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:15:48

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - orfloresti/devtalks-xss
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: XSSveil
👤 项目作者: Manif3stVoid
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 03:04:31

📝 项目描述:
Blind XSS detection built on interact.sh — per-field tokenized payloads, injection-pointvulnerable-URL correlation, screenshot/DOM capture, and a persistent-session reverse proxy. Authorized testing only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #DOM

📦 项目名称: DOM-Based-XSS-in-Pocket-Mobile-Android-iOS-Unsanitized-WebView-HTML-Injection-since-13-Year
👤 项目作者: FUNFACTOR1
🛠 开发语言: Unknown
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 19:35:40

📝 项目描述:
0-click XSS (CWE-79) in Mozilla Pocket Android v8.33.0.0 via unsanitized $(document.body).html(content) in articleview-mobile.js. Background service triggers execution without user interaction. Java bridge exposed. Reported to Mozilla Security 2024-07-10. Won't Fix. CVE pending.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC #CVE #Reflected #DOM

📦 项目名称: xss2shell
👤 项目作者: Christbowel
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 08:42:41

📝 项目描述:
xss2shell poc and detector

🔗 点击访问项目地址 GitHub - Christbowel/xss2shell: xss2shell poc and detector
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected #DOM

📦 项目名称: detonate
👤 项目作者: santhreal
🛠 开发语言: Rust
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 07:59:22

📝 项目描述:
Prove an injected web payload actually EXECUTES (alert(1) fires), not just reflects (a shared XSS-execution oracle over Santh's jsdet sandbox).

🔗 点击访问项目地址 GitHub - santhreal/detonate: Prove an injected web payload actually EXECUTES (alert(1) fires), not just reflects (a shared XSS…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #DOM

📦 项目名称: cyberstart
👤 项目作者: bugninja-sketch
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 06:52:35

📝 项目描述:
Interactive cybersecurity demo playground built for OWASP JISU SIP Program — CyberStart 2026, covering DevTools, Phishing, SQL Injection, XSS & Password Hashing with a live quiz and leaderboard.

🔗 点击访问项目地址 GitHub - bugninja-sketch/cyberstart: Interactive cybersecurity demo playground built for OWASP JISU SIP Program — CyberStart 2026…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: xss-learning-log
👤 项目作者: Daddypool-44418
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 03:42:14

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - Daddypool-44418/xss-learning-log
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #DOM

📦 项目名称: mitigator
👤 项目作者: MohamedSoliman21
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-04 22:00:23

📝 项目描述:
A production-grade, zero-trust security library for Node.js & TypeScript. Defends against OWASP Top 10, Prototype Pollution, XSS, SQLi, and Path Traversal with WebAuthn, AES-256-GCM, Adaptive Rate Limiting, and Winternitz PQC.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Stored #Reflected #DOM

📦 项目名称: xss-attack-defense-lab
👤 项目作者: calsgnkadir
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-04 06:49:38

📝 项目描述:
Hands-on XSS attack & defense research on OWASP Juice Shop, PortSwigger & self-authored labs (Burp Suite + DevTools).

🔗 点击访问项目地址 GitHub - calsgnkadir/xss-attack-defense-lab: Hands-on XSS attack & defense research on OWASP Juice Shop, PortSwigger & self-authored…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected #DOM

📦 项目名称: dom-based-cross-site-scripting
👤 项目作者: qeeqbox
🛠 开发语言: Unknown
Star数量: 4 | 🍴 Fork数量: 2
📅 更新时间: 2026-08-04 04:13:55

📝 项目描述:
A threat actor may inject malicious content into webapp. The payload is not reflected in the HTTP request and response, then executed in the victim's browser

🔗 点击访问项目地址 GitHub - qeeqbox/dom-based-cross-site-scripting: A threat actor may inject malicious content into webapp. The payload is not reflected…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: dom-xss-lab
👤 项目作者: uells
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 15:42:47

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected #DOM

📦 项目名称: juice-shop-pentest
👤 项目作者: aryaparge
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 10:47:22

📝 项目描述:
Manual web application penetration testing of OWASP Juice Shop using Burp Suite Community Edition. Identified and validated SQL Injection, XSS, Broken Access Control, Sensitive Data Exposure, and Business Logic vulnerabilities, with findings documented in a professional penetration testing report.

🔗 点击访问项目地址 GitHub - aryaparge/juice-shop-pentest: Manual web application penetration testing of OWASP Juice Shop using Burp Suite Community…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected #DOM

📦 项目名称: XSSurge
👤 项目作者: ssn-code
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 04:29:42

📝 项目描述:
Advanced XSS detection suite with context-aware payload generation, custom HTML/JS parsing, intelligent fuzzing, fast crawling, and DOM/reflected XSS scanning. Includes WAF detection/evasion, parameter discovery, outdated JS library checks, blind XSS support, and extensible attack workflows.

🔗 点击访问项目地址 GitHub - ssn-code/XSSurge: Advanced XSS detection suite with context-aware payload generation, custom HTML/JS parsing, intelligent…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: XSSscan
👤 项目作者: wqnmlgb151
🛠 开发语言: Go
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-02 17:07:24

📝 项目描述:
下一代上下文感知 XSS 扫描器 — 19种注入上下文、反射/存储/DOM/Blind XSS检测、WAF绕过、CSP分析、自动化报告

🔗 点击访问项目地址 GitHub - wqnmlgb151/XSSscan: 下一代上下文感知 XSS 扫描器 — 19种注入上下文、反射/存储/DOM/Blind XSS检测、WAF绕过、CSP分析、自动化报告
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: Behelit
👤 项目作者: indra-031
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-02 16:17:16

📝 项目描述:
A lightweight Chrome Extension for discovering potential DOM XSS vulnerabilities directly in your browser.

🔗 点击访问项目地址 GitHub - indra-031/Behelit: A lightweight Chrome Extension for discovering potential DOM XSS vulnerabilities directly in your browser.
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: purifai
👤 项目作者: moji2002
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-02 14:04:19

📝 项目描述:
Zero-dependency strip-to-text HTML sanitizer with contextual output encoding for Node.js, browsers, and edge runtimes.

🔗 点击访问项目地址 GitHub - moji2002/purifai: Zero-dependency strip-to-text HTML sanitizer with contextual output encoding for Node.js, browsers,…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #DOM

📦 项目名称: wraith
👤 项目作者: Arcanum-Sec
🛠 开发语言: JavaScript
Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-01 22:39:49

📝 项目描述:
WRAITH — a modern browser-hooking framework (BeEF + blind-XSS successor) for red teams, researchers, and educators. For authorized security testing, research & education only.

🔗 点击访问项目地址 GitHub - Arcanum-Sec/wraith: WRAITH — a modern browser-hooking framework (BeEF + blind-XSS successor) for red teams, researchers…
 
 
Back to Top