# EdOverflow/bugbounty-cheatsheet

A list of interesting payloads, tips and tricks for bug bounty hunters.

Repository: https://github.com/EdOverflow/bugbounty-cheatsheet
Canonical: https://ross.abutalabs.com/products/bugbounty-cheatsheet
License: CC-BY-SA-4.0
License Family: other
Topics: security, payloads, infosec, bugbounty
Last push: 2023-09-14T05:50:48+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 3338, "days_push": 1084, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 6536, forks 1621 (observed 2026-08-28T04:09:45.040594+00:00)

## What it is
A curated cheat sheet of payloads, tips, and tricks for bug bounty hunters, covering vulnerabilities like XSS, SQLi, SSRF, XXE, and RCE. It also includes references to bug bounty platforms, books, recon resources, and practice platforms.

## Use cases
- find xss payloads for bug bounty hunting
- learn common sqli injection payloads
- reference ssrf and xxe attack techniques
- get tips for starting in bug bounties
- find bug bounty platforms and practice labs
- look up open redirect and template injection tricks

## When to choose
- you are a bug bounty hunter needing quick payload references
- you are learning web security vulnerabilities hands-on
- you want a community-maintained collection of attack payloads and recon tips

## When to avoid
- you need an automated scanning or exploitation tool rather than reference material
- you require up-to-date payloads for the latest CVEs, as the repo is in maintenance mode
- you need formal security training or structured coursework

## Facets
- artifact type: learning-resource
- maturity: maintenance
- function: security, penetration-testing, developer-tools
- domain: security, penetration-testing, tutorials
- platform: cross-platform
- tags: bug-bounty, cheatsheet, payloads, infosec, xss, sqli, ssrf

## Member repositories
- EdOverflow/bugbounty-cheatsheet (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:45.040594+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:44:07.378921+00:00, confidence not recorded.
  - readme: https://github.com/EdOverflow/bugbounty-cheatsheet (fetched 2026-08-28T04:09:45.040594+00:00, sha 7092ba20b2e8)
- Data as of 2026-08-30T08:39:29.467469+00:00.
