Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Categories
  3. Security
  4. Web Security

Web Security

The "Awesome Web Security" project is a curated collection of resources focused on the security of web applications and services. Web security encompasses practices and technologies designed to protect websites and online services from cyber threats, vulnerabilities, and attacks. This list includes tools for penetration testing, secure coding practices, frameworks, libraries, and educational materials such as articles and tutorials. It is valuable for developers, security professionals, and researchers who seek to enhance their understanding of web security and implement robust security measures. Users can find essential tools and knowledge to safeguard their web applications effectively and stay ahead of potential threats.

web-securitycybersecuritypenetration-testingsecure-codingvulnerabilitiesweb-appssecurity-tools
RSSView on GitHub
13.2k stars1.8k forks0 contributorsUpdated
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub

Related Awesome Lists

📦
Hacking

The "Awesome Hacking" project is a curated resource list designed for those interested in the field of hacking, which involves exploring and exploiting vulnerabilities in computer systems and networks. This list encompasses a wide range of categories, including penetration testing tools, ethical hacking tutorials, security research papers, and community forums. It serves as a valuable resource for beginners looking to learn the basics of cybersecurity, as well as experienced professionals seeking advanced techniques and tools. Whether you are aiming to enhance your skills or stay updated on the latest security trends, this collection offers a wealth of information to support your hacking journey.

16.1k
📦
Security

The "Awesome Security" project is a curated collection of resources focused on enhancing security practices in the digital realm. This list encompasses a wide range of categories including security tools, libraries, frameworks, tutorials, and best practices for various platforms and technologies. It is designed to benefit security professionals, developers, and system administrators alike, providing valuable insights and tools to safeguard applications and data. Whether you are a beginner looking to understand security fundamentals or an experienced practitioner seeking advanced techniques, this project offers a wealth of information to help you improve your security posture and protect your digital assets.

14.2k
📦
Malware Analysis

The "Awesome Malware Analysis" project is a curated resource list designed to assist security professionals and researchers in the field of malware analysis. Malware analysis involves examining malicious software to understand its behavior, functionality, and impact. This list includes tools for static and dynamic analysis, reverse engineering resources, malware databases, and educational materials such as tutorials and courses. It is valuable for both beginners looking to learn the basics and experienced analysts seeking advanced techniques and tools. Users can find a wealth of resources to enhance their skills and improve their malware analysis capabilities.

13.6k
📦
CTF

The "Awesome CTF" project is a curated collection of resources focused on Capture The Flag (CTF) competitions, which are events that challenge participants to solve cybersecurity problems and vulnerabilities. This list encompasses a variety of categories including CTF platforms, write-ups, tools, training materials, and community forums, catering to both newcomers and seasoned cybersecurity enthusiasts. Whether you are looking to sharpen your skills, participate in competitions, or learn from past challenges, this repository provides invaluable insights and resources. Dive into the world of CTFs and enhance your cybersecurity prowess with the tools and knowledge available here.

11.4k

Table of Contents

79 sections · 377 projects

Digests

8 projects
Hacker101
hacker101.com
The Daily Swig - Web security digest
portswigger.net
Web Application Security Zone by Netsparker
netsparker.com
Infosec Newbie
sneakymonkey.net
The Magic of Learning
bitvijays.github.io
CTF Field Guide
trailofbits.github.io
PayloadsAllTheThings
PayloadsAllTheThings

A comprehensive collection of payloads and bypass techniques for web application security testing and penetration testing.

Python79,3268 days ago
tl;dr sec
tldrsec.com

Forums

6 projects
Phrack Magazine
phrack.org
The Hacker News
thehackernews.com
Security Weekly
securityweekly.com
The Register
theregister.co.uk
Dark Reading
darkreading.com
HackDig
en.hackdig.com

- Cross-Site Scripting

6 projects
Cross-Site Scripting – Application Security – Google
google.com
H5SC
H5SC

A comprehensive collection of HTML5-related XSS attack vectors and testing resources for web security professionals.

JavaScript2,9424 years ago
AwesomeXSS
AwesomeXSS

A curated collection of XSS resources including payloads, polyglots, bypass techniques, and tools for security researchers.

JavaScript5,1321 year ago
XSS.png
XSS.png

A comprehensive mind map for understanding and exploring Cross-Site Scripting (XSS) attack vectors and techniques.

5510 years ago
C.XSS Guide
excess-xss.com
THE BIG BAD WOLF - XSS AND MAINTAINING ACCESS
paulosyibelo.com

Prototype Pollution

3 projects
Prototype pollution attack in NodeJS application
Prototype pollution attack in NodeJS application

Research presentation and paper analyzing prototype pollution attacks in Node.js, presented at NorthSec 2018.

JavaScript5402 years ago
Exploiting prototype pollution – RCE in Kibana (CVE-2019-7609)
research.securitum.com
Real-world JS - 1
blog.p6.is

CSV Injection

2 projects
CSV Injection -> Meterpreter on Pornhub
news.webamooz.com
The Absurdly Underestimated Dangers of CSV Injection
georgemauer.net