swisskyrepo

    swisskyrepo/PayloadsAllTheThings

    #352 this week

    A list of useful payloads and bypass for Web Application Security and Pentest/CTF

    security
    bounty
    bugbounty
    bypass
    cheatsheet
    enumeration
    Python
    MIT
    79.0K stars
    17.1K forks
    79.0K GitHub watchers
    Updated 7/7/2026
    View on GitHub

    Backblaze Generative Media Hackathon

    Build the next generation of AI media apps with Genblaze, stored on Backblaze B2. $10,000 in prizes.

    Enter the hackathon

    Loading star history...

    Use Cases & Benefits

    • Provides a comprehensive list of payloads and bypass techniques for web application security testing and penetration testing.
    • Includes detailed vulnerability descriptions, exploit methods, and Burp Intruder payload sets, primarily using Python and markdown documentation.
    • Highly popular and actively maintained since 2016 with nearly 70k stars and over 15k forks, indicating strong community adoption and trust.
    • Open-source under MIT license, encouraging contributions and continuous updates from security researchers and pentesters worldwide.
    • Ideal for security professionals, bug bounty hunters, and CTF participants seeking practical payloads and methodologies for web app vulnerability exploitation.

    About PayloadsAllTheThings

    Payloads All The Things

    A list of useful payloads and bypasses for Web Application Security. Feel free to improve with your payloads and techniques !

    You can also contribute with a :beers: IRL, or using the sponsor button.

    Sponsor Tweet

    An alternative display version is available at PayloadsAllTheThingsWeb.

    banner

    :book: Documentation

    Every section contains the following files, you can use the _template_vuln folder to create a new chapter:

    • README.md - vulnerability description and how to exploit it, including several payloads
    • Intruder - a set of files to give to Burp Intruder
    • Images - pictures for the README.md
    • Files - some files referenced in the README.md

    You might also like the other projects from the AllTheThings family :

    You want more ? Check the Books and Youtube channel selections.

    :technologist: Contributions

    Be sure to read CONTRIBUTING.md

    sponsors-list

    Thanks again for your contribution! :heart:

    :beers: Sponsors

    This project is proudly sponsored by these companies.

    LogoDescription
    sponsor-serpapiSerpApi is a real time API to access Google search results. It solves the issues of having to rent proxies, solving captchas, and JSON parsing.
    sponsor-projectdiscoveryProjectDiscovery - Detect real, exploitable vulnerabilities. Harness the power of Nuclei for fast and accurate findings without false positives.
    sponsor-vaadataVAADATA - Ethical Hacking Services

    Discover Repositories

    Search across tracked repositories by name or description