Arsenly
Tools
Free Tools
Pricing
Resources
Sign in Get started
← All tools

Payload Generator

Payloads & Wordlists

Build tuned XSS, SQLi, NoSQLi, command-injection, LFI, SSTI, XXE, CRLF and polyglot payloads - with your own values and nine encoders.

What is Payload Generator?

Payload Generator produces ready-to-use offensive payloads across 15 web-vulnerability classes - XSS, SQLi, NoSQLi, command injection, LFI, SSTI, XXE, CRLF, LDAP, XPath, SSI/ESI, CSV/formula, Host-header, GraphQL and polyglots - each with WAF-bypass variants and a one-line note on what it does and when to use it.

Rather than copy-pasting static cheat-sheet strings, you drop in your own value - the JavaScript to run, the command, the file to read - plus an optional out-of-band host for blind/exfil payloads, and every payload is rewritten with it. A 9-option encoder (URL, double-URL, full-URL, Base64, HTML entities/hex, \u and \x) then applies on top so you can slip past filters.

Filter the list, copy a single payload or the whole set, or download it as a wordlist for your fuzzer.

What it generates

  • XSS - body/attribute/URI/JS contexts, base64-wrapped and case-mangled bypasses.
  • SQLi & NoSQLi - boolean, union, error- and time-based (MySQL/MSSQL/PG) and Mongo operator injection.
  • Command injection - Unix & Windows chaining, substitution, IFS bypass and OOB confirm.
  • LFI / path traversal - encoding tricks, PHP wrappers (filter/data/expect) and null-byte.
  • SSTI & XXE - engine-detection + RCE (Jinja2/Twig/SpEL/FreeMarker) and file-read/OOB XXE.
  • CRLF & polyglots - header injection, response splitting and multi-context polyglots.
  • Custom value + OOB host substitution, plus nine encoders applied live.

Where it fits in your workflow

  • Drop context-appropriate payloads straight into a request or proxy.
  • Generate WAF-bypass and encoded variants when a base payload is blocked.
  • Export a category as a wordlist for ffuf / Intruder.
Use Payload Generator

Sign in to access this tool.

Create free account Sign in

At a glance

CategoryPayloads & Wordlists
RunsIn your browser
Token cost Free - no tokens
Access Free
Status● Live

Frequently asked questions

What does the “Value” field do?

It substitutes into the payloads - for XSS it is the JavaScript to run, for command injection the command, for LFI the target file, and so on. The optional OOB host fills blind/exfil payloads. Everything is generated in your browser.

Where are SSRF / open-redirect payloads?

Those live in the dedicated SSRF Toolkit, which also builds the matching ffuf/curl commands and IP-encoding bypasses.

Explore more tools →