# lutfumertceylan/top25-parameter

For basic researches, top 25 vulnerability parameters that can be used in automation tools or manual recon. 🛡️⚔️🧙

Repository: https://github.com/lutfumertceylan/top25-parameter
Canonical: https://ross.abutalabs.com/products/top25-parameter
Homepage: https://owasp.org/www-project-top-25-parameters/
License: NOASSERTION
License Family: other
Topics: vulnerability-detection, vulnerability-research, bugbounty, pentesting, pentest-tool, bugbountytips, security, infosec, xss-detection
Last push: 2024-06-09T23:36:24+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2319, "days_push": 815, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1847, forks 282 (observed 2026-08-28T04:05:43.525826+00:00)

## What it is
OWASP Top 25 Parameters is a curated reference dataset of the 25 most commonly vulnerable parameter names for six vulnerability classes (XSS, SSRF, LFI, SQLi, RCE, open redirect). It is intended for use in automation tools or manual reconnaissance during bug bounty and penetration testing.

## Use cases
- find vulnerable parameters during web recon
- build wordlists for bug bounty automation
- test for xss ssrf sqli lfi rce and open redirect parameters
- prioritize parameters to fuzz in pentests
- learn common vulnerable parameter names

## When to choose
- you need a quick curated list of high-frequency vulnerable parameters for recon or fuzzing
- you are doing bug bounty or manual penetration testing research

## When to avoid
- you need a full vulnerability scanner rather than a parameter reference list
- you need guaranteed up-to-date or statistically proven parameter frequencies

## Facets
- artifact type: dataset
- maturity: stable
- function: security, penetration-testing, vulnerability-scanning
- domain: security, penetration-testing, osint
- platform: cli, cross-platform
- tags: bug-bounty, wordlist, recon, xss, ssrf, sqli, lfi, rce, open-redirect, owasp

## Member repositories
- lutfumertceylan/top25-parameter (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:43.525826+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:17:50.819738+00:00, confidence not recorded.
  - readme: https://github.com/lutfumertceylan/top25-parameter (fetched 2026-08-28T04:05:43.525826+00:00, sha b6a06f7b20a6)
  - homepage: https://owasp.org/www-project-top-25-parameters/ (fetched 2026-08-29T10:56:55.855292+00:00, sha 9e23056a134c)
  - site_page: https://owasp.org/about (fetched 2026-08-29T10:56:55.857713+00:00, sha b21a48297b2d)
- Data as of 2026-08-30T08:39:29.467469+00:00.
