# RenwaX23/XSS-Payloads

List of XSS Vectors/Payloads

Repository: https://github.com/RenwaX23/XSS-Payloads
Canonical: https://ross.abutalabs.com/products/xss-payloads
License Family: other
Last push: 2026-01-14T07:36:12+00:00

## Health v2 (maintenance only)
Score: 60/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 62, release rhythm 35, longevity 100
- inputs: {"age_days": 3009, "days_push": 231, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1391, forks 271 (observed 2026-08-28T04:04:35.908214+00:00)

## What it is
A curated collection of cross-site scripting (XSS) vectors and payloads gathered since 2015 from websites, tweets, and books. It includes a notable list of payloads that work without parentheses, aimed at bypassing WAFs and finding XSS vulnerabilities.

## Use cases
- find xss payloads for bug bounty hunting
- bypass waf filters during penetration testing
- learn cross-site scripting attack vectors
- reference list of xss payloads without parentheses
- study web security injection techniques

## When to choose
- you need a quick reference of XSS vectors including parenthesis-free variants
- you are doing manual penetration testing or bug bounty research on web apps
- you want a community-collected payload list to complement other cheat sheets

## When to avoid
- you need up-to-date, actively maintained payloads - the author recommends the PortSwigger XSS cheat sheet instead
- you want an automated XSS scanning tool rather than a static payload list
- you need a tool with a license or formal support

## Facets
- artifact type: learning-resource
- maturity: maintenance
- function: security, penetration-testing
- domain: security, penetration-testing, web-development
- platform: cross-platform
- tags: xss, payloads, cheat-sheet, waf-bypass, bug-bounty, web-security

## Member repositories
- RenwaX23/XSS-Payloads (main) score 60

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:35.908214+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:39:35.261281+00:00, confidence not recorded.
  - readme: https://github.com/RenwaX23/XSS-Payloads (fetched 2026-08-28T04:04:35.908214+00:00, sha e48df8516b2c)
- Data as of 2026-08-30T08:39:29.467469+00:00.
