We Stand For Peace and With the Palestinian People 🇵🇸
No more worries about getting notified of non-existing vulnerabilities.
From false-positive free results to clear & dynamically generated steps-to-reproduce.
Frequently asked questions
What types of XSS vulnerabilities can XSScanner detect?
XSScanner is capable of identifying and verifying GET-based & POST-based cross-site scripting vulnerabilities at the moment. Including ones that require additional input from the user to trigger (view our demo video for more information)!
Can I scan multiple URLs at the same time?
Yes, you can manually supply multiple URLs at the same time.
Additionally, you can also initiate a Deep Scan and automate the whole process from content discovery to scanning for CWE-79!
Is XSSCANNER capable of finding DOM-based cross-site scripting vulnerabilities?
No, at the moment, only GET-based & POST-based XSS vulnerabilities are supported.
Later generations of our XSScanner will include support for DOM-based XSS.
Is XSSCANNER capable of finding CSP-bypasses?
No, the first generation of XSSCANNER is currently not capable of finding more advanced CSP bypasses for certain edge-cases.
Later generations of our XSScanner will include full support for Content Security Policy bypasses.
Is XSSCANNER capable of scanning authenticated parts of my website?
Yes it is! You can easily supply request headers (including any authentication headers) to reach parts behind a login form!
Is XSSCANNER capable of finding Blind XSS?
Yes, Blind XSS is supported using our integrated callback server. Our XSS scanner automatically injects payloads with your personal blind XSS payload.