Web Application Tools

462 tools
Joomscan
Joomscan
Open Source Kali Web Application

OWASP Joomla vulnerability scanner. Detects Joomla version, components, modules, and templates with known vulnerabilities. Checks for common…

joomscan
joomscan
Open Source Exploitation Web Application

OWASP Joomla Vulnerability Scanner Project https://www.secologist.com/

jQuery-with-XSS
jQuery-with-XSS
Free Web Application

jQuery with XSS, Testing and Secure Version

jsscm
jsscm
Open Source Exploitation Web Application

JSSCM detects expired domains for Stored XSS exploitation during browsing.

juice-shop
juice-shop
Open Source Web Application

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

juice-shop-ctf
juice-shop-ctf
Open Source Web Application

Tool to export Juice Shop challenges and hints in data format compatible with CTFd, RootTheBox or FBCTF

Juice-Shop-Write-up
Juice-Shop-Write-up
Free Web Application

Non-official write up for the Juice-Shop CTF

JWT_Tool
JWT_Tool
Open Source Web Application

Toolkit for testing, tampering, and forging JSON Web Tokens. Tests common JWT vulnerabilities including algorithm confusion (alg:none, RS256…

jwt-cracker
jwt-cracker
Open Source Password Attacks Web Application

Simple HS256, HS384 & HS512 JWT token brute force cracker.

jwt-pwn
jwt-pwn
Open Source Web Application

Security Testing Scripts for JWT

jwtcat
jwtcat
Open Source Web Application

A CPU-based JSON Web Token (JWT) cracker and - to some extent - scanner.

JWTweak
JWTweak
Free Web Application

Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.

JYso
JYso
Open Source Web Application

JYso

keyFinder
keyFinder
Open Source Reconnaissance Web Application

Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

killshot
killshot
Free Exploitation Reconnaissance

A Penetration Testing Framework, Information gathering tool & Website Vulnerability Scanner

knoxsser
knoxsser
Open Source Web Application

A powerful bash script for massive XSS scanning leveraging Brute Logic's KNOXSS API

kubernetes-goat
kubernetes-goat
Open Source Exploitation Web Application

Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on play…

lamp-cloud
lamp-cloud
Open Source Web Application

[灯灯]微服务中后台快速开发平台,支持jdk21、jdk17、jdk8,专注于多租户、开放平台解决方案,亦可作为普通项目(非SaaS架构)的基础开发框架使用,目前已实现插拔式数据库隔离、SCHEMA隔离、字段隔离 等租户隔离方案。

laravel-xss-protection
laravel-xss-protection
Open Source Web Application

Laravel XSS Protection Middleware

latte
latte
Free Web Application

☕ Latte: the safest & truly intuitive templates for PHP. Engine for those who want the most secure PHP sites.

LazyXss
LazyXss
Free Web Application

Automation tool to testing and confirm the xss vulnerability.

Learn-Web-Hacking
Learn-Web-Hacking
Free Web Application

Study Notes For Web Hacking / Web安全学习笔记

LFImap
LFImap
Open Source Exploitation Web Application

Local File Inclusion discovery and exploitation tool

LFITester
LFITester
Open Source Exploitation Scanning & Enumeration

LFITester is a Python3 program that automates the detection and exploitation of Local File Inclusion (LFI) vulnerabilities on a server.