PayloadsAllTheThings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Github stars Tracking Chart

Payloads All The Things Tweet

A list of useful payloads and bypasses for Web Application Security.
Feel free to improve with your payloads and techniques !
I :heart: pull requests :)

You can also contribute with a :beers: IRL, or using the sponsor button.

Every section contains the following files, you can use the _template_vuln folder to create a new chapter:

  • README.md - vulnerability description and how to exploit it, including several payloads
  • Intruder - a set of files to give to Burp Intruder
  • Images - pictures for the README.md
  • Files - some files referenced in the README.md

You might also like the Methodology and Resources folder :

You want more ? Check the Books and Youtube videos selections.

Main metrics

Overview
Name With Ownerswisskyrepo/PayloadsAllTheThings
Primary LanguagePython
Program languagePHP (Language Count: 12)
Platform
License:MIT License
所有者活动
Created At2016-10-18 07:29:07
Pushed At2025-08-03 14:33:50
Last Commit At2025-08-03 16:32:40
Release Count7
Last Release Name4.2 (Posted on )
First Release Name1.0 (Posted on )
用户参与
Stargazers Count69.1k
Watchers Count1.9k
Fork Count15.8k
Commits Count2.1k
Has Issues Enabled
Issues Count0
Issue Open Count0
Pull Requests Count542
Pull Requests Open Count17
Pull Requests Close Count134
项目设置
Has Wiki Enabled
Is Archived
Is Fork
Is Locked
Is Mirror
Is Private