Cheatsheets
Ready-to-copy payloads, bypasses and commands. A quick reference for every vulnerability type.
XSS Cheatsheet
Cross-Site Scripting
SSRF Cheatsheet
Server-Side Request Forgery
SQLi Cheatsheet
SQL Injection
IDOR Cheatsheet
Insecure Direct Object Reference
CSRF Cheatsheet
Cross-Site Request Forgery
Open Redirect Cheatsheet
Open Redirect
XXE Cheatsheet
XML External Entity
Path Traversal Cheatsheet
Directory Traversal / LFI
CORS Cheatsheet
Cross-Origin Resource Sharing
OAuth Cheatsheet
OAuth / OpenID Connect
Race Condition Cheatsheet
Race Conditions
File Upload Cheatsheet
File Upload Vulnerabilities
GraphQL Cheatsheet
GraphQL API Security
WebSockets Cheatsheet
WebSocket Attacks
SSTI Cheatsheet
Server-Side Template Injection
Command Injection Cheatsheet
OS Command Injection
NoSQL Injection Cheatsheet
NoSQL Injection (MongoDB)
JWT Cheatsheet
JSON Web Token Attacks
Want more complete guides with methodology and real cases?
View full guides- hunters training
- 711
- labs from real reports
- 55
- completions
- 1,205
- in bounties practiced
- $213,970
hunters training
labs from real reports
completions
in bounties practiced
Stop reading about bugs and start hunting them
Create your free account and practice on labs based on real reports that paid out thousands of euros. The Academy is free forever.
No card · free Academy · cancel anytime