# hakluke/weaponised-XSS-payloads

XSS payloads designed to turn alert(1) into P1

Repository: https://github.com/hakluke/weaponised-XSS-payloads
Canonical: https://ross.abutalabs.com/products/weaponised-xss-payloads
Language: JavaScript
License Family: other
Last push: 2023-09-12T12:44:23+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 2663, "days_push": 1086, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1404, forks 222 (observed 2026-08-28T04:04:38.076590+00:00)

## What it is
A collection of weaponised XSS payloads - JavaScript files that perform sensitive actions (like creating admin users) on popular CMS platforms when loaded via an XSS vulnerability. It helps pentesters and bug bounty hunters demonstrate real impact by chaining XSS into critical findings such as account takeover.

## Use cases
- upgrade XSS findings from medium to critical severity
- demonstrate account takeover via stored XSS in a pentest report
- create admin users through XSS on WordPress
- chain XSS bugs into P1 bug bounty reports
- show real security impact of reflected XSS vulnerabilities

## When to choose
- you need to prove business impact of an XSS bug in a pentest or bug bounty
- you are testing popular CMS platforms like WordPress for XSS escalation
- you want ready-made JavaScript payloads for authorized security testing

## When to avoid
- you need a general XSS scanner or detection tool
- you are looking for XSS prevention or sanitization libraries
- you lack authorization to test the target system

## Facets
- artifact type: library
- maturity: maintenance
- function: security, penetration-testing
- domain: security, web-development, penetration-testing
- platform: browser
- tags: xss-payloads, bug-bounty, exploitation, javascript-payloads, cms-exploits, web-server

## Member repositories
- hakluke/weaponised-XSS-payloads (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:38.076590+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:38:50.778244+00:00, confidence not recorded.
  - readme: https://github.com/hakluke/weaponised-XSS-payloads (fetched 2026-08-28T04:04:38.076590+00:00, sha c97ce1efe21b)
- Data as of 2026-08-30T08:39:29.467469+00:00.
