xss-grenade
Modern XSS vulnerability scanner for real-world web applications.
File Explorer
- screenshot.jpg
- xss_grenade.png
- assign.tmpl
- documentwrite.tmpl
- documentwriteln.tmpl
- eval.tmpl
- formaction.tmpl
- function.tmpl
- inlineevent.tmpl
- innerHtml.tmpl
- jshref.tmpl
- onclickAddEventListener.tmpl
- onclickSetAttribute.tmpl
- rangeCreateContextualFragment.tmpl
- replace.tmpl
- setTimeout.tmpl
- baseURI.tmpl
- documentURI.tmpl
- location.hash.tmpl
- location.tmpl
- locationhref.tmpl
- locationpathname.tmpl
- locationsearch.tmpl
- URL.tmpl
- URLUnencoded.tmpl
- address.tmpl
- attribute_name.tmpl
- attribute_quoted.tmpl
- attribute_script.tmpl
- attribute_singlequoted.tmpl
- attribute_unquoted.tmpl
- body.tmpl
- body_comment.tmpl
- css_import.tmpl
- css_style.tmpl
- css_style_font_value.tmpl
- css_style_value.tmpl
- form.tmpl
- form_in_new_window.tmpl
- head.tmpl
- href.tmpl
- iframe_attribute_value.tmpl
- iframe_srcdoc.tmpl
- js_assignment.tmpl
- js_comment.tmpl
- js_escape_doublequotes_eval.tmpl
- js_eval.tmpl
- js_eventhandler_quoted.tmpl
- js_eventhandler_singlequoted.tmpl
- js_eventhandler_unquoted.tmpl
- js_quoted_string.tmpl
- js_singlequoted_string.tmpl
- js_slashquoted_string.tmpl
- json.tmpl
- noscript.tmpl
- object_data.tmpl
- object_param.tmpl
- script_src.tmpl
- style_attribute_value.tmpl
- tagname.tmpl
- textarea.tmpl
- textarea_attribute_value.tmpl
- title.tmpl
- benchmark_firingrange.py
- fr_groundtruth.json
- fr_oracle.py
- fr_server.py
- LICENSE.firing-range
- README.md
- .gitignore
- _attack_graph_v2_source.py
- _auth.py
- _blind_xss_oob.py
- _breakout_synth.py
- _cache_poisoning.py
- _checkpoint.py
- _css_injection.py
- _dom_clobbering.py
- _dom_exploit_engine.py
- _dom_v6.py
- _dompurify_config.py
- _dompurify_cve_feed.py
- _engine.py
- _exploit_classifier.py
- _finding_scorer.py
- _finding_store.py
- _graphql_xss.py
- _headless_crawler.py
- _headless_verifier.py
- _html_analyzer.py
- _html_report.py
- _htmx_alpine.py
- _js_analyzer.py
- _library_cve_feed.py
- _markdown_xss.py
- _mutation_xss.py
- _oob_collector.py
- _open_redirect.py
- _param_wordlist.py
- _poc_generator.py
- _proto_pollution_analyzer.py
- _render_gate.py
- _response_aware.py
- _sarif_report.py
- _sourcemap_analyzer.py
- _spa_route_extractor.py
- _static_js_analyzer.py
- _stored_xss_tracker.py
- _template_injection.py
- _trusted_types_analyzer.py
- _url_analyzer.py
- benchmark_scoreboard.py
- context_engine.py
- destructive_real_test_server.py
- dom_hooks_v6.js
- head2head_dalfox.py
- LICENSE
- payloads.txt
- profile_phases.py
- README.md
- repro_level2.py
- requirements.txt
- xss_grenade.py
- xss_grenade_gui.py
- xssgrenade_app.py
# Use via CDN
jsDelivrjsDelivr serves any public GitHub repository as a CDN with zero setup. Pick a version and a file to get a ready-to-paste link and snippet.
Link
Example
// repository documentation
Was this content helpful?
(0 ratings)
