A curated repository of categorized payloads for testing and exploiting common web vulnerabilities in ethical hacking and penetration testing.
-
Updated
May 14, 2025 - PHP
A curated repository of categorized payloads for testing and exploiting common web vulnerabilities in ethical hacking and penetration testing.
An alternative solution(as a Magento 2 extension) to fix the XXE vulnerability CVE-2024-34102(aka Cosmic Sting). If you cannot upgrade Magento or cannot apply the official patch, try this one.
A replacement of `\Magento\Framework\Xml\Security` for Magento 2 with enhanced XML Security.
This repository contains various XXE labs set up for different languages and their different parsers. This may alternatively serve as a playground to teach or test with Vulnerability scanners / WAF rules / Secure Configuration settings.
The PHP sandbox environment is a Docker-based tool for testing XML processing code, with XXE vulnerabilities demonstrated and security considerations explained.
pwnig all the (web)things
Add a description, image, and links to the xxe topic page so that developers can more easily learn about it.
To associate your repository with the xxe topic, visit your repo's landing page and select "manage topics."