Tools
Tool · dast/web-app-scanneractivehigh-riskdual-uselicence

XSSer

XSSer (Cross Site Scripter) is an automated framework to detect, exploit and report XSS vulnerabilities in web apps, shipping 1,500+ attack vectors with a context-aware validation engine, WAF bypassers and encoding evasion, injection across GET/POST params, cookies and DOM, and PDF/XML/JSON reporting. Python 3 with CLI and GTK GUI.

Use responsibly

Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.

High risk of account lockouts, WAF bans, and terms-of-service violations. Requires explicit authorization and small, targeted inputs.

More tools