Check your WAF before an attacker does
-
Updated
Jul 17, 2025 - Python
Check your WAF before an attacker does
Automatic SSTI detection tool with interactive interface
Waymap is a fast and optimized web vulnerability scanner built for penetration testers. It helps in identifying vulnerabilities by testing against various payloads.
Websites Vulnerability Scanner
App with Server Side Template Injection (SSTI) vulnerability - possible RCE - in Flask. Free vulnerable app for ethical hacking / penetration testing training.
A script written in python3 to spread blind cross-site scripting payloads on HTTP requests headers
is a PoC for CVE-2024-4040 tool for exploiting the SSTI vulnerability in CrushFTP
Serverside Template Injection (SSTI) RCE - THM challenge "whiterose"
FastAPI app with Jinja2 SSTI vulnerability example to demonstrate security risks in web applications.
An Intentionally Vulnerable SSTI application for a beginner to an experienced.
Vulnerable PWA
Test your SSTI skills in this CTF challenge running in Docker
Simple ssti payload generator for java using concat technique
A simple automation tool to detect LFI, RCE and SSTI vulnerability. Forked for PR and customization
Add a description, image, and links to the ssti topic page so that developers can more easily learn about it.
To associate your repository with the ssti topic, visit your repo's landing page and select "manage topics."