Is there an extensive checklist of web vulnerabilities?

This page summarizes the projects mentioned and recommended in the original post on /r/Hacking_Tutorials

Our great sponsors
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • WorkOS - The modern identity platform for B2B SaaS
  • SaaSHub - Software Alternatives and Reviews
  • web-pentesting-checklist

    checklist for testing the web applications

  • wstg

    The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • OWASP-Testing-Checklist

    OWASP based Web Application Security Testing Checklist is an Excel based checklist which helps you to track the status of completed and pending test cases.

  • Here’s a excel checklist: https://github.com/tanprathan/OWASP-Testing-Checklist

  • PayloadsAllTheThings

    A list of useful payloads and bypass for Web Application Security and Pentest/CTF

  • Its not a "checklist" but maybe it can help https://github.com/swisskyrepo/PayloadsAllTheThings/

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts