xxe-injection-payload-list

XML payload list

Lists examples and types of XML external entity injection payloads and attacks

🎯 XML External Entity (XXE) Injection Payload List

GitHub

1k stars
23 watching
305 forks
last commit: about 2 years ago
Linked from 1 awesome list

bug-bountybugbountycyber-securitycybersecurityhackinginformation-securityinfosecpayloadpayloadsweb-application-securitywebsecuritywebsecurity-referencexmlxml-entityxxexxe-examplexxe-injectionxxe-payloadxxe-payload-listxxe-payloads

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
payloadbox/rfi-lfi-payload-listProvides examples and explanations of vulnerabilities in web applications545
payloadbox/open-redirect-payload-listA list of examples and explanations for protecting against open redirect vulnerabilities in web applications.541
whitel1st/docemA tool to embed malicious payloads in various document formats553
luisfontes19/xxexploiterAn application used to exploit XXE vulnerabilities by generating XML payloads and serving them to test web applications.547
jbarone/xxelabA proof-of-concept web application demonstrating an XML External Entity vulnerability225
mik0w/pallmsA collection of payloads designed to exploit vulnerabilities in large language models.70
vp777/metahttpAutomates scanning of HTTP resources in a target network using XML External Entity (XXE) attacks37
swisskyrepo/payloadsallthethingsA comprehensive collection of tools and techniques for web application security testing and exploitation61,904
pallets/markupsafeProtects against injection attacks by safely escaping untrusted strings in HTML and XML markup637
xx0hcd/alt-beacon-payloadCreates a custom C# beacon payload with AV bypass and shellcode injection capabilities20
enjoiz/xxeinjectorAutomates exploitation of XXE vulnerability using various methods to retrieve files and data from vulnerable applications.1,556
xyele/hackerone_wordlistA curated list of common words and phrases used in hacking attempts to aid in security testing and assessment0
deepcake/chickensAn example of using an entity-component system framework with game engines and physics libraries to create interactive content1
buffalowill/oxml_xxeA tool for exploiting XXE vulnerabilities in various file formats1,049
twentygototen/insertoptionsloopholePrevents users from bypassing predefined insert options by validating and enforcing insertion rules1