⚠ Authorized testing only. Disclosed public bug-bounty data for defensive/educational research. Use payloads only against systems you are permitted to test.
LogoThe Hacktivity Field GuideReal-world web hacking, catalogued
🔎
Field Guide/Payload Libraries

Payload Libraries

Copy-pasteable, report-cited payloads harvested from the disclosed HackerOne corpus. Replace placeholders (TARGET, COLLAB, VICTIM) with your authorized target and collaborator. Each payload links back to the report it came from; open hackerone.com/reports/<id> for context.

LibraryClass page
xss.mdvulnerabilities/xss
sqli.mdvulnerabilities/sqli
ssrf.mdvulnerabilities/ssrf
command-injection.mdvulnerabilities/command-injection
code-injection.mdvulnerabilities/code-injection
ssti.mdvulnerabilities/ssti
path-traversal.mdvulnerabilities/path-traversal
open-redirect.mdvulnerabilities/open-redirect
xxe.mdvulnerabilities/xxe
request-smuggling.mdvulnerabilities/request-smuggling
crlf-http-splitting.mdvulnerabilities/crlf-http-splitting
deserialization.mdvulnerabilities/deserialization

> These are real payloads from disclosed reports, provided for authorized testing and defensive > research only. Test only systems you have permission to test.