Build tuned XSS, SQLi, NoSQLi, command-injection, LFI, SSTI, XXE, CRLF and polyglot payloads - with your own values and nine encoders.
Payload Generator produces ready-to-use offensive payloads across 15 web-vulnerability classes - XSS, SQLi, NoSQLi, command injection, LFI, SSTI, XXE, CRLF, LDAP, XPath, SSI/ESI, CSV/formula, Host-header, GraphQL and polyglots - each with WAF-bypass variants and a one-line note on what it does and when to use it.
Rather than copy-pasting static cheat-sheet strings, you drop in your own value - the JavaScript to run, the command, the file to read - plus an optional out-of-band host for blind/exfil payloads, and every payload is rewritten with it. A 9-option encoder (URL, double-URL, full-URL, Base64, HTML entities/hex, \u and \x) then applies on top so you can slip past filters.
Filter the list, copy a single payload or the whole set, or download it as a wordlist for your fuzzer.
It substitutes into the payloads - for XSS it is the JavaScript to run, for command injection the command, for LFI the target file, and so on. The optional OOB host fills blind/exfil payloads. Everything is generated in your browser.
Those live in the dedicated SSRF Toolkit, which also builds the matching ffuf/curl commands and IP-encoding bypasses.