swisskyrepo

    swisskyrepo/PayloadsAllTheThings

    #315 this week

    A list of useful payloads and bypass for Web Application Security and Pentest/CTF

    security
    bounty
    bugbounty
    bypass
    cheatsheet
    enumeration
    Python
    MIT
    81.0K stars
    17.4K forks
    81.0K GitHub watchers
    Updated 9/21/2026
    View on GitHub

    Build with Backblaze B2

    SDKs, agent skills, IDE extensions, and reference pipelines from Backblaze Labs. All open source.

    Explore Backblaze Labs

    Loading star history...

    Use Cases & Benefits

    • Provides a comprehensive collection of payloads and bypass techniques for web application security testing and penetration testing.
    • Offers an extensive, well-organized resource that covers a wide range of vulnerabilities with practical exploitation examples and ready-to-use payloads.
    • Use for preparing and executing web application penetration tests with ready-made payloads to identify security weaknesses.
    • Use for learning and practicing exploitation techniques in Capture The Flag (CTF) competitions and security training.
    • Use for developing custom payloads and bypasses by leveraging the structured templates and community contributions.

    About PayloadsAllTheThings

    Payloads All The Things

    A list of useful payloads and bypasses for Web Application Security. Feel free to improve with your payloads and techniques !

    You can also contribute with a :beers: IRL, or using the sponsor button.

    Sponsor Tweet

    An alternative display version is available at PayloadsAllTheThingsWeb.

    banner

    :book: Documentation

    Every section contains the following files, you can use the _template_vuln folder to create a new chapter:

    • README.md - vulnerability description and how to exploit it, including several payloads
    • Intruder - a set of files to give to Burp Intruder
    • Images - pictures for the README.md
    • Files - some files referenced in the README.md

    You might also like the other projects from the AllTheThings family :

    You want more ? Check the Books and Youtube channel selections.

    :technologist: Contributions

    Be sure to read CONTRIBUTING.md

    sponsors-list

    Thanks again for your contribution! :heart:

    :beers: Sponsors

    This project is proudly sponsored by these companies.

    LogoDescription
    sponsor-serpapiSerpApi is a real time API to access Google search results. It solves the issues of having to rent proxies, solving captchas, and JSON parsing.
    sponsor-projectdiscoveryProjectDiscovery - Detect real, exploitable vulnerabilities. Harness the power of Nuclei for fast and accurate findings without false positives.
    sponsor-vaadataVAADATA - Ethical Hacking Services

    Discover Repositories

    Search across tracked repositories by name or description