swisskyrepo

    swisskyrepo/PayloadsAllTheThings

    A list of useful payloads and bypass for Web Application Security and Pentest/CTF

    security
    bounty
    bugbounty
    bypass
    cheatsheet
    enumeration
    hacking
    hacktoberfest
    methodology
    payload
    payloads
    penetration-testing
    pentest
    privilege-escalation
    redteam
    vulnerability
    web-application
    Python
    MIT
    74.0K stars
    16.4K forks
    74.0K watching
    Updated 2/27/2026
    View on GitHub
    Backblaze Advertisement

    Loading star history...

    Health Score

    75

    Weekly Growth

    +0

    +0.0% this week

    Contributors

    1

    Total contributors

    Open Issues

    17

    Generated Insights

    About PayloadsAllTheThings

    Payloads All The Things

    A list of useful payloads and bypasses for Web Application Security. Feel free to improve with your payloads and techniques !

    You can also contribute with a :beers: IRL, or using the sponsor button.

    Sponsor Tweet

    An alternative display version is available at PayloadsAllTheThingsWeb.

    banner

    :book: Documentation

    Every section contains the following files, you can use the _template_vuln folder to create a new chapter:

    • README.md - vulnerability description and how to exploit it, including several payloads
    • Intruder - a set of files to give to Burp Intruder
    • Images - pictures for the README.md
    • Files - some files referenced in the README.md

    You might also like the other projects from the AllTheThings family :

    You want more ? Check the Books and Youtube channel selections.

    :technologist: Contributions

    Be sure to read CONTRIBUTING.md

    sponsors-list

    Thanks again for your contribution! :heart:

    :beers: Sponsors

    This project is proudly sponsored by these companies.

    LogoDescription
    sponsor-serpapiSerpApi is a real time API to access Google search results. It solves the issues of having to rent proxies, solving captchas, and JSON parsing.
    sponsor-projectdiscoveryProjectDiscovery - Detect real, exploitable vulnerabilities. Harness the power of Nuclei for fast and accurate findings without false positives.
    sponsor-vaadataVAADATA - Ethical Hacking Services

    Discover Repositories

    Search across tracked repositories by name or description