Ross ROSS = Recommend OSS · open-source software intelligence for agents

hakluke/weaponised-XSS-payloads

XSS payloads designed to turn alert(1) into P1 observed · 2026-08-28

github.com/hakluke/weaponised-XSS-payloads · JavaScript observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2663
  • days_rel: n/a
  • days_push: 1086
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1404 stars · 222 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A collection of weaponised XSS payloads - JavaScript files that perform sensitive actions (like creating admin users) on popular CMS platforms when loaded via an XSS vulnerability. It helps pentesters and bug bounty hunters demonstrate real impact by chaining XSS into critical findings such as account takeover.

Use cases

  • upgrade XSS findings from medium to critical severity
  • demonstrate account takeover via stored XSS in a pentest report
  • create admin users through XSS on WordPress
  • chain XSS bugs into P1 bug bounty reports
  • show real security impact of reflected XSS vulnerabilities

When to choose

  • you need to prove business impact of an XSS bug in a pentest or bug bounty
  • you are testing popular CMS platforms like WordPress for XSS escalation
  • you want ready-made JavaScript payloads for authorized security testing

When to avoid

  • you need a general XSS scanner or detection tool
  • you are looking for XSS prevention or sanitization libraries
  • you lack authorization to test the target system

Facets

library · maturity maintenance

security penetration-testing security web-development penetration-testing browser xss-payloads bug-bounty exploitation javascript-payloads cms-exploits web-server

1 source

Member repositories

RepositoryRoleHealth v2
hakluke/weaponised-XSS-payloadsmain32

For agents

markdown · JSON · MCP: product_card(name="hakluke/weaponised-XSS-payloads")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem