diff --git a/addons/index.html b/addons/index.html index 7da19bb9db..c4ddf2b33c 100644 --- a/addons/index.html +++ b/addons/index.html @@ -827,7 +827,7 @@

ZAP Marketplace

Repository - Download + Download @@ -840,7 +840,7 @@

ZAP Marketplace

commonlib - 1.37.0 + 1.38.0 release @@ -849,7 +849,7 @@

ZAP Marketplace

ZAP Dev Team - 2025-10-07 + 2025-10-21 @@ -2731,7 +2731,7 @@

ZAP Marketplace

Repository - Download + Download @@ -2744,7 +2744,7 @@

ZAP Marketplace

pscanrules - 67 + 68 release @@ -2753,7 +2753,7 @@

ZAP Marketplace

ZAP Dev Team - 2025-09-18 + 2025-10-21 @@ -3421,7 +3421,7 @@

ZAP Marketplace

Repository - Download + Download @@ -3434,7 +3434,7 @@

ZAP Marketplace

selenium - 15.40.0 + 15.41.0 release @@ -3443,7 +3443,7 @@

ZAP Marketplace

ZAP Dev Team - 2025-09-02 + 2025-10-21 diff --git a/docs/desktop/addons/common-library/alerttags/index.html b/docs/desktop/addons/common-library/alerttags/index.html index fdaf544ed0..641906571d 100644 --- a/docs/desktop/addons/common-library/alerttags/index.html +++ b/docs/desktop/addons/common-library/alerttags/index.html @@ -1870,6 +1870,9 @@

Compliance Tags CVE Tags

Any alert that involves a specific CVE will (generally) also have a tag for that specific CVE identifier with a value that links to Mitre’s National Vulnerability Database (NVD).

+

SYSTEMIC Tag

+

The SYSTEMIC tag is used to flag alerts that are often “Site wide”. These include most rules related to headers. From ZAP 2.17.0 only a limited number of systemic alerts will be included in the Desktop UI and reports by default.

+

Policy Tags

The add-on also provides a set of Alert Tags which associate various rule types or focus areas to scan policies, see the Scan Policies add-on help for further details.

diff --git a/docs/desktop/addons/passive-scan-rules/index.html b/docs/desktop/addons/passive-scan-rules/index.html index 853d3b78d0..855f97fe5b 100644 --- a/docs/desktop/addons/passive-scan-rules/index.html +++ b/docs/desktop/addons/passive-scan-rules/index.html @@ -2096,14 +2096,14 @@

Off-site Redirect PII Disclosure

PII is information like credit card number, SSN etc. This check currently reports only numbers which match credit card numbers and pass Luhn checksum, which gives high confidence, that this is a credit card number.
-At MEDIUM and HIGH threshold it attempts to use three characters of context on each side of potential matches to exclude matches within decimal like content. At LOW threshold, alerts will be raised for such matches.

+At MEDIUM and HIGH threshold it attempts to use three characters of context on each side of potential matches to exclude matches within decimal like content or content which includes underscores. At LOW threshold, alerts will be raised for such matches.

At MEDIUM and HIGH threshold, the following content types are evaluated:

-

Image and CSS files are always ignored. Every other content type is evaluated at LOW threshold.

+

Image and CSS files are always ignored. Every other content type is evaluated at LOW threshold. Additionally at LOW threshold the entire HTML response is evaluated.

Note: In the case of suspected credit card values, the potential credit card numbers are looked up against a Bank Identification Number List (BINList). If a match is found the alert is raised at High confidence and additional details are added to the ‘Other Information’ field in the alert, otherwise the alerts will have Medium confidence. diff --git a/docs/sbom/commonlib/index.html b/docs/sbom/commonlib/index.html index 1382baad8f..124f85a2d0 100644 --- a/docs/sbom/commonlib/index.html +++ b/docs/sbom/commonlib/index.html @@ -122,9 +122,9 @@

Common Library Add-on SBOM

Common Library
-

This page contains a list of all the libraries involved in building version 1.37.0 of the +

This page contains a list of all the libraries involved in building version 1.38.0 of the "Common Library" add-on. -

You may download the full Software Bill Of Materials (SBOM) JSON file +

You may download the full Software Bill Of Materials (SBOM) JSON file for this add-on.

@@ -209,7 +209,7 @@

Common Library Add-on SBOM

- + @@ -221,13 +221,13 @@

Common Library Add-on SBOM

- + - + @@ -239,7 +239,7 @@

Common Library Add-on SBOM

- + @@ -255,6 +255,12 @@

Common Library Add-on SBOM

+ + + + + + @@ -263,7 +269,7 @@

Common Library Add-on SBOM

- + @@ -275,13 +281,13 @@

Common Library Add-on SBOM

- + - + @@ -293,13 +299,13 @@

Common Library Add-on SBOM

- + - + @@ -341,31 +347,25 @@

Common Library Add-on SBOM

- + - + - + - - - - - - - + @@ -377,7 +377,7 @@

Common Library Add-on SBOM

- + @@ -395,31 +395,31 @@

Common Library Add-on SBOM

- + - + - + - + - + @@ -459,21 +459,27 @@

Common Library Add-on SBOM

+ + + + + + - + - + - + @@ -485,31 +491,31 @@

Common Library Add-on SBOM

- + - + - + - + - + @@ -581,49 +587,49 @@

Common Library Add-on SBOM

- + - + - + - + - + - + - + - + @@ -665,19 +671,19 @@

Common Library Add-on SBOM

- + - + - + diff --git a/docs/sbom/index.html b/docs/sbom/index.html index 50c4f4d119..72ce0f88f1 100644 --- a/docs/sbom/index.html +++ b/docs/sbom/index.html @@ -233,7 +233,7 @@

Software Bill of Materials

Common Library Add-on SBOM @@ -503,7 +503,7 @@

Software Bill of Materials

Passive scanner rules Add-on SBOM @@ -620,7 +620,7 @@

Software Bill of Materials

Selenium Add-on SBOM diff --git a/docs/sbom/pscanrules/index.html b/docs/sbom/pscanrules/index.html index 30cdbbc6dc..d46919989b 100644 --- a/docs/sbom/pscanrules/index.html +++ b/docs/sbom/pscanrules/index.html @@ -122,9 +122,9 @@

Passive scanner rules Add-on SBOM

Passive scanner rules
-

This page contains a list of all the libraries involved in building version 67 of the +

This page contains a list of all the libraries involved in building version 68 of the "Passive scanner rules" add-on. -

You may download the full Software Bill Of Materials (SBOM) JSON file +

You may download the full Software Bill Of Materials (SBOM) JSON file for this add-on.

biz.aQute.bnd.annotation6.4.17.1.0 (Apache-2.0 OR EPL-2.0)
byte-buddy1.14.111.17.7 Apache-2.0
byte-buddy-agent1.14.111.17.7 Apache-2.0
checker-qual3.37.03.43.0 MIT
Apache-2.0
commons-codec1.19.0Apache-2.0
commons-collections 3.2.2
commons-collections44.44.5.0 Apache-2.0
commons-csv1.10.01.12.0 Apache-2.0
commons-csv1.12.01.14.1 Apache-2.0
commons-io2.16.12.18.0 Apache-2.0
commons-io2.18.02.20.0 Apache-2.0
error_prone_annotation2.36.02.42.0 Apache-2.0
error_prone_annotations2.36.02.42.0 Apache-2.0
error_prone_check_api2.36.02.42.0 Apache-2.0
error_prone_core2.36.0Apache-2.0
error_prone_type_annotations2.36.02.42.0 Apache-2.0
failureaccess1.0.11.0.2 Apache-2.0
google-java-format1.19.11.27.0 Apache-2.0
guava32.1.3-jre33.4.0-jre Apache-2.0
hamcrest2.23.0 BSD-3-Clause
hamcrest-core2.23.0 BSD-3-Clause
hamcrest-library2.23.0 BSD-3-Clause
Apache-2.0
j2objc-annotations3.0.0Apache-2.0
jackson-annotations2.19.12.20 Apache-2.0
jackson-bom2.19.12.20.0 Apache-2.0
jackson-core2.19.12.20.0 Apache-2.0
jackson-databind2.19.12.20.0 Apache-2.0
jackson-dataformat-xml2.19.12.20.0 Apache-2.0
jackson-dataformat-yaml2.19.12.20.0 Apache-2.0
jackson-datatype-jdk82.19.12.20.0 Apache-2.0
jackson-datatype-jsr3102.19.12.20.0 Apache-2.0
junit-bom5.10.26.0.0 EPL-2.0
junit-jupiter5.10.26.0.0 EPL-2.0
junit-jupiter-api5.10.26.0.0 EPL-2.0
junit-jupiter-engine5.10.26.0.0 EPL-2.0
junit-jupiter-params5.10.26.0.0 EPL-2.0
junit-platform-commons1.10.26.0.0 EPL-2.0
junit-platform-engine1.10.26.0.0 EPL-2.0
junit-platform-launcher1.10.26.0.0 EPL-2.0
lombok1.18.361.18.40 MIT
mockito-core5.10.05.20.0 MIT
mockito-junit-jupiter5.10.05.20.0 MIT
- 128 + 129
- 132 + 133
- 177 + 178
@@ -209,7 +209,7 @@

Passive scanner rules Add-on SBOM

- + @@ -221,13 +221,13 @@

Passive scanner rules Add-on SBOM

- + - + @@ -239,13 +239,13 @@

Passive scanner rules Add-on SBOM

- + - + @@ -261,6 +261,12 @@

Passive scanner rules Add-on SBOM

+ + + + + + @@ -269,7 +275,7 @@

Passive scanner rules Add-on SBOM

- + @@ -281,13 +287,13 @@

Passive scanner rules Add-on SBOM

- + - + @@ -299,13 +305,13 @@

Passive scanner rules Add-on SBOM

- + - + @@ -353,31 +359,25 @@

Passive scanner rules Add-on SBOM

- + - + - + - - - - - - - + @@ -389,7 +389,7 @@

Passive scanner rules Add-on SBOM

- + @@ -407,31 +407,31 @@

Passive scanner rules Add-on SBOM

- + - + - + - + - + @@ -449,7 +449,7 @@

Passive scanner rules Add-on SBOM

- + @@ -477,21 +477,27 @@

Passive scanner rules Add-on SBOM

+ + + + + + - + - + - + @@ -503,31 +509,31 @@

Passive scanner rules Add-on SBOM

- + - + - + - + - + @@ -599,49 +605,49 @@

Passive scanner rules Add-on SBOM

- + - + - + - + - + - + - + - + @@ -683,19 +689,19 @@

Passive scanner rules Add-on SBOM

- + - + - + @@ -863,7 +869,7 @@

Passive scanner rules Add-on SBOM

- + diff --git a/docs/sbom/selenium/index.html b/docs/sbom/selenium/index.html index 5249c36d76..47061a1d4a 100644 --- a/docs/sbom/selenium/index.html +++ b/docs/sbom/selenium/index.html @@ -122,9 +122,9 @@

Selenium Add-on SBOM

Selenium
-

This page contains a list of all the libraries involved in building version 15.40.0 of the +

This page contains a list of all the libraries involved in building version 15.41.0 of the "Selenium" add-on. -

You may download the full Software Bill Of Materials (SBOM) JSON file +

You may download the full Software Bill Of Materials (SBOM) JSON file for this add-on.

biz.aQute.bnd.annotation6.4.17.1.0 (Apache-2.0 OR EPL-2.0)
byte-buddy1.14.91.17.7 Apache-2.0
byte-buddy-agent1.14.91.17.7 Apache-2.0
checker-qual3.37.03.43.0 MIT
commonlib1.36.01.38.0
Apache-2.0
commons-codec1.19.0Apache-2.0
commons-collections 3.2.2
commons-collections44.44.5.0 Apache-2.0
commons-csv1.10.01.12.0 Apache-2.0
commons-csv1.12.01.14.1 Apache-2.0
commons-io2.16.12.18.0 Apache-2.0
commons-io2.18.02.20.0 Apache-2.0
error_prone_annotation2.36.02.42.0 Apache-2.0
error_prone_annotations2.36.02.42.0 Apache-2.0
error_prone_check_api2.36.02.42.0 Apache-2.0
error_prone_core2.36.0Apache-2.0
error_prone_type_annotations2.36.02.42.0 Apache-2.0
failureaccess1.0.11.0.2 Apache-2.0
google-java-format1.19.11.27.0 Apache-2.0
guava32.1.3-jre33.4.0-jre Apache-2.0
hamcrest2.23.0 BSD-3-Clause
hamcrest-core2.23.0 BSD-3-Clause
hamcrest-library2.23.0 BSD-3-Clause
htmlunit-csp4.0.04.17.0 Apache-2.0
Apache-2.0
j2objc-annotations3.0.0Apache-2.0
jackson-annotations2.19.12.20 Apache-2.0
jackson-bom2.19.12.20.0 Apache-2.0
jackson-core2.19.12.20.0 Apache-2.0
jackson-databind2.19.12.20.0 Apache-2.0
jackson-dataformat-xml2.19.12.20.0 Apache-2.0
jackson-dataformat-yaml2.19.12.20.0 Apache-2.0
jackson-datatype-jdk82.19.12.20.0 Apache-2.0
jackson-datatype-jsr3102.19.12.20.0 Apache-2.0
junit-bom5.10.16.0.0 EPL-2.0
junit-jupiter5.10.16.0.0 EPL-2.0
junit-jupiter-api5.10.16.0.0 EPL-2.0
junit-jupiter-engine5.10.16.0.0 EPL-2.0
junit-jupiter-params5.10.16.0.0 EPL-2.0
junit-platform-commons1.10.16.0.0 EPL-2.0
junit-platform-engine1.10.16.0.0 EPL-2.0
junit-platform-launcher1.10.16.0.0 EPL-2.0
lombok1.18.361.18.40 MIT
mockito-core5.7.05.20.0 MIT
mockito-junit-jupiter5.7.05.20.0 MIT
re2j1.71.8 Go License
@@ -215,7 +215,7 @@

Selenium Add-on SBOM

- + @@ -227,13 +227,13 @@

Selenium Add-on SBOM

- + - + @@ -245,13 +245,13 @@

Selenium Add-on SBOM

- + - + @@ -273,6 +273,12 @@

Selenium Add-on SBOM

+ + + + + + @@ -281,7 +287,7 @@

Selenium Add-on SBOM

- + @@ -293,13 +299,13 @@

Selenium Add-on SBOM

- + - + @@ -315,12 +321,6 @@

Selenium Add-on SBOM

- - - - - - @@ -383,31 +383,31 @@

Selenium Add-on SBOM

- + - + - - + + - - + + - - + + @@ -419,7 +419,7 @@

Selenium Add-on SBOM

- + @@ -443,37 +443,37 @@

Selenium Add-on SBOM

- + - + - + - + - + - + @@ -579,21 +579,27 @@

Selenium Add-on SBOM

+ + + + + + - + - + - + @@ -605,31 +611,31 @@

Selenium Add-on SBOM

- + - + - + - + - + @@ -701,49 +707,49 @@

Selenium Add-on SBOM

- + - + - + - + - + - + - + - + @@ -785,19 +791,19 @@

Selenium Add-on SBOM

- + - + - + @@ -905,7 +911,7 @@

Selenium Add-on SBOM

- + @@ -917,67 +923,67 @@

Selenium Add-on SBOM

- + - + - + - + - + - + - + - + - + - + - + @@ -1043,103 +1049,103 @@

Selenium Add-on SBOM

- + - + - + - - + + - - + + - - + + - + - + - + - + - + - + - + - + - + - + - + diff --git a/search/index.json b/search/index.json index b8b00fbe03..3d3dd6b4c6 100644 --- a/search/index.json +++ b/search/index.json @@ -1045,7 +1045,7 @@ "keywords": ["","alert","tags"], "tags": null, "summary": "\u003ch1 id=\"alert-tags\"\u003eAlert Tags\u003c/h1\u003e\n\u003cp\u003eThe Common Library add-on provides Alert Tags for use by scan rules.\u003c/p\u003e\n\u003cp\u003eOf note the following tags/groups of tags are included:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCustom Payloads - A tag which indicates the scan rules which support \u003ca href=\"/docs/desktop/addons/custom-payloads/\"\u003eCustom Payloads functionality\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eHIPAA (Health Insurance Portability and Accountability Act) - A tag representing alerts/rules which we\u0026rsquo;ve mapped to the HIPAA standard.\u003c/li\u003e\n\u003cli\u003eOWASP Top 10 (2017) - Tags representing the risks/vulnerabilities from the 2017 OWASP Top 10 list.\u003c/li\u003e\n\u003cli\u003eOWASP Top 10 (2021) - Tags representing the risks/vulnerabilities from the 2021 OWASP Top 10 list.\u003c/li\u003e\n\u003cli\u003ePCI DSS (Payment Card Industry Data Security Standard) - A tag representing alerts/rules which we\u0026rsquo;ve mapped to the PCI DSS standard.\u003c/li\u003e\n\u003cli\u003eTest Timing - A tag which represent rules/alerts which are based on time (induced delay) payloads.\u003c/li\u003e\n\u003cli\u003eOWASP Web Security Testing Guide (v4.2) - Tags which map rules/alerts to the relevant sections of the OWASP WSTG (version 4.2).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2 id=\"compliance\"\u003eCompliance Tags \u003ca class=\"header-link\" href=\"#compliance\"\u003e\u003csvg class=\"fill-current o-60 hover-accent-color-light\" height=\"22px\" viewBox=\"0 0 24 24\" width=\"22px\" xmlns=\"http://www.w3.org/2000/svg\"\u003e\u003cpath d=\"M0 0h24v24H0z\" fill=\"none\"/\u003e\u003cpath d=\"M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z\" fill=\"currentColor\"/\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/h2\u003e\n\u003cp\u003ePlease note that the PCI DSS and HIPAA standards deal with specific types of data, while an identified vulnerability may expose such data ZAP has insufficient context with which to differentiate what is or might be exposed by leveraging a given vulnerability. If the system being tested does not hold any such data then the related compliance tag \u003cstrong\u003emay\u003c/strong\u003e not be relevant.\u003c/p\u003e", - "content": "alert tags common library addon provides use by scan rules note following tagsgroups included: custom payloads tag which indicates support functionality hipaa health insurance portability accountability act representing alertsrules weve mapped standard owasp top 10 2017 risksvulnerabilities from list 2021 pci dss payment card industry data security test timing represent rulesalerts based time induced delay web testing guide v42 map relevant sections wstg version 42 compliance please that standards deal specific types while identified vulnerability may expose such zap has insufficient context differentiate what might exposed leveraging given system being tested does not hold any then related see also: cve involves will generally also have identifier value links mitres national database nvd policy set associate various rule focus areas policies help further details " + "content": "alert tags common library addon provides use by scan rules note following tagsgroups included: custom payloads tag which indicates support functionality hipaa health insurance portability accountability act representing alertsrules weve mapped standard owasp top 10 2017 risksvulnerabilities from list 2021 pci dss payment card industry data security test timing represent rulesalerts based time induced delay web testing guide v42 map relevant sections wstg version 42 compliance please that standards deal specific types while identified vulnerability may expose such zap has insufficient context differentiate what might exposed leveraging given system being tested does not hold any then related see also: cve involves will generally also have identifier value links mitres national database nvd systemic used flag alerts often site wide these include most headers 2170 only limited number included desktop ui reports default policy set associate various rule focus areas policies help further details " }, { "url": "/docs/desktop/addons/authentication-helper/autodetect-auth/", @@ -8333,7 +8333,7 @@ "keywords": ["","marketplace","zap"], "tags": null, "summary": "\u003cp\u003eZAP Marketplace contains ZAP add-ons which have been written by the ZAP team and the community. The add-ons help to extend the functionalities of ZAP.\nIf you are using the latest version of ZAP then you can browse and download add-ons from within ZAP by clicking on this button in the toolbar:\u003c/p\u003e", - "content": "zap marketplace contains addons which have been written by team community help extend functionalities you using latest version then can browse download from within clicking button toolbar: also import that downloaded manually via file load addon menu option desktop would like publish your own follow how guide name id status author last updated access control testing adds set tools web applications accesscontrol 10 alpha dev 20240325 active scanner rules release ascanrules 74 20250918 ascanrulesalpha 52 20251007 beta ascanrulesbeta 62 advanced sqlinjection injection bundle sqli derived sqlmap sqliplugin 16 andrea pompili yhawke 20250430 ajax spider allows sites make heavy use javascript crawljax spiderajax 23260 20250902 alert filters automate changing risk levels alertfilters 24 20250620 all one notes simple extension view pane allinonenotes david vassallo 20211007 attack surface detector analyzes application source code generate endpoints used penetration attacksurfacedetector 114 secure decisions matthew deletto 20190307 authentication helper helps identify up handling authhelper 0290 statistics records logged inout contexts scope authstats automation framework 0530 beanshell console provides browser render html responses browserview 20230313 bug tracker bugtracker 20220923 call graph user selected resources callgraph colm o39flaherty home handles calls services callhome 0150 client side integration exposes information firefox chrome extensions 0170 collection: pentester pack collection ideal pentesters packpentester 010 20220512 scan just containing packscanrules 001 20220513 common library other commonlib 1370 scripts useful communityscripts 19 20240701 core language files translations corelang 15 20220214 custom payloads ability add edit remove ie scanners custompayloads database engines related infrastructure 080 20250304 development 0100 20250515 diff displays dialog showing differences between requests uses diffutils diffmatchpatch 17 20250109 directory list v10 names forced fuzzer directorylistv1 v23 lists directorylistv23 lc lower case directorylistv23lc dom xss rule domxss 22 aabha biyani 20250710 encoder encodedecodehash support scripted processors 170 eval villain when launched evalvillain 040 dennis goodlett 20241125 fileupload detect upload them find vulnerabilities 121 ksasan preetkaran20gmailcom 20231023 browsing directories owasp dirbuster tool bruteforce 18 20250827 fuzzai 20240924 fuzzdb offensive backdoors manual may flagged antivirus fuzzdboffensive 20240111 fuzz 13160 getting started short gettingstarted graalvm engine scripting graaljs graphql inspect 0280 20250326 groovy 320 20240411 grpc decode protobuf messages 020 20240702 arabic helparsa crowdin 20250821 bosnian helpbsba chinese simplified helpzhcn english 21 filipino helpfilph french helpfrfr 11 indonesian helpidid japanese helpjajp malay helpmsmy portuguese brazilian helpptbr 12 russian helpruru spanish helpeses turkish helptrtr highlighter highlight strings request response tabs hud heads display 0190 20240507 image location privacy passive imagelocationscanner jay ball veggiespam importexport export functionality exim thatsn0tmysite invoke external passing context such urls parameters json shows nicely formatted jsonview juha kiveks 20230907 jwt 103 20230102 kotlin 110 stackhawk engineering levoai build openapi specs traffic 030 20240710 linux webdrivers webdriverlinux 162 20251015 macos webdrivermacos map local mapping content chosen maplocal keindel andrey maksimov 20231005 neonmarker colors history table items based tags 180 kingthorin 20250214 network networking capabilities 0230 oast exploit outofband 0220 online menus onlinemenu 14 imports spiders definitions 46 plus joanna bona nathalie bouchahine artur grzesica mohammad kamar markus kiss michal materniak marcin spiewak sda se open industry solutions 20250910 parameter digger hidden unlinked finding cache poisoning paramdigger arkaprabha chakraborty 20240715 scanning pscan 050 pscanrules 67 pscanrulesalpha pscanrulesbeta plugnhack configuration supports mozilla standard: https:developermozillaorgenusdocsplugnhack 13 20221027 postman collections 070 python templates included jython quick start tab quickly test target quickstart reflect finds reflected 0011 caleb kinney 20210219 regular expression tester expressions regextester replacer easy way replace 20 20250110 report generation official reports 0410 20250904 requester send 780 surikato retest presenceabsence previously generated alerts 0110 retirejs vulnerable outdated packages retire 0490 nikita mundhada reveal show fields enable disabled revisit site any time past session ruby jruby saml 20221028 policies standard scanpolicies script jsr 223 languages 45140 selenium webdriver provider includes htmlunit 15400 sequence gives possibility defining scanned serversent events sse communication 20240521 soap scans wsdl 28 alberto albertov91 43 software manager data xml directly server srm 202590 black duck inc 20250926 automatically uris 0160 svn svndigger technology detection various fingerprints identifiers wappalyzer 21480 tips tricks token analysis analyze pseudo random tokens those csrf protection tokengen treetools tree carl sampson value generator define field values submitting app added modified enableddisabled deleted formhandler 670 viewstate aspjsf decoder editor calum hutton websockets websocket 33 windows webdriverwindows 163 zest graphical security zaps macro steroids 4890 " + "content": "zap marketplace contains addons which have been written by team community help extend functionalities you using latest version then can browse download from within clicking button toolbar: also import that downloaded manually via file load addon menu option desktop would like publish your own follow how guide name id status author last updated access control testing adds set tools web applications accesscontrol 10 alpha dev 20240325 active scanner rules release ascanrules 74 20250918 ascanrulesalpha 52 20251007 beta ascanrulesbeta 62 advanced sqlinjection injection bundle sqli derived sqlmap sqliplugin 16 andrea pompili yhawke 20250430 ajax spider allows sites make heavy use javascript crawljax spiderajax 23260 20250902 alert filters automate changing risk levels alertfilters 24 20250620 all one notes simple extension view pane allinonenotes david vassallo 20211007 attack surface detector analyzes application source code generate endpoints used penetration attacksurfacedetector 114 secure decisions matthew deletto 20190307 authentication helper helps identify up handling authhelper 0290 statistics records logged inout contexts scope authstats automation framework 0530 beanshell console provides browser render html responses browserview 20230313 bug tracker bugtracker 20220923 call graph user selected resources callgraph colm o39flaherty home handles calls services callhome 0150 client side integration exposes information firefox chrome extensions 0170 collection: pentester pack collection ideal pentesters packpentester 010 20220512 scan just containing packscanrules 001 20220513 common library other commonlib 1380 20251021 scripts useful communityscripts 19 20240701 core language files translations corelang 15 20220214 custom payloads ability add edit remove ie scanners custompayloads database engines related infrastructure 080 20250304 development 0100 20250515 diff displays dialog showing differences between requests uses diffutils diffmatchpatch 17 20250109 directory list v10 names forced fuzzer directorylistv1 v23 lists directorylistv23 lc lower case directorylistv23lc dom xss rule domxss 22 aabha biyani 20250710 encoder encodedecodehash support scripted processors 170 eval villain when launched evalvillain 040 dennis goodlett 20241125 fileupload detect upload them find vulnerabilities 121 ksasan preetkaran20gmailcom 20231023 browsing directories owasp dirbuster tool bruteforce 18 20250827 fuzzai 20240924 fuzzdb offensive backdoors manual may flagged antivirus fuzzdboffensive 20240111 fuzz 13160 getting started short gettingstarted graalvm engine scripting graaljs graphql inspect 0280 20250326 groovy 320 20240411 grpc decode protobuf messages 020 20240702 arabic helparsa crowdin 20250821 bosnian helpbsba chinese simplified helpzhcn english 21 filipino helpfilph french helpfrfr 11 indonesian helpidid japanese helpjajp malay helpmsmy portuguese brazilian helpptbr 12 russian helpruru spanish helpeses turkish helptrtr highlighter highlight strings request response tabs hud heads display 0190 20240507 image location privacy passive imagelocationscanner jay ball veggiespam importexport export functionality exim thatsn0tmysite invoke external passing context such urls parameters json shows nicely formatted jsonview juha kiveks 20230907 jwt 103 20230102 kotlin 110 stackhawk engineering levoai build openapi specs traffic 030 20240710 linux webdrivers webdriverlinux 162 20251015 macos webdrivermacos map local mapping content chosen maplocal keindel andrey maksimov 20231005 neonmarker colors history table items based tags 180 kingthorin 20250214 network networking capabilities 0230 oast exploit outofband 0220 online menus onlinemenu 14 imports spiders definitions 46 plus joanna bona nathalie bouchahine artur grzesica mohammad kamar markus kiss michal materniak marcin spiewak sda se open industry solutions 20250910 parameter digger hidden unlinked finding cache poisoning paramdigger arkaprabha chakraborty 20240715 scanning pscan 050 pscanrules 68 pscanrulesalpha pscanrulesbeta plugnhack configuration supports mozilla standard: https:developermozillaorgenusdocsplugnhack 13 20221027 postman collections 070 python templates included jython quick start tab quickly test target quickstart reflect finds reflected 0011 caleb kinney 20210219 regular expression tester expressions regextester replacer easy way replace 20 20250110 report generation official reports 0410 20250904 requester send 780 surikato retest presenceabsence previously generated alerts 0110 retirejs vulnerable outdated packages retire 0490 nikita mundhada reveal show fields enable disabled revisit site any time past session ruby jruby saml 20221028 policies standard scanpolicies script jsr 223 languages 45140 selenium webdriver provider includes htmlunit 15410 sequence gives possibility defining scanned serversent events sse communication 20240521 soap scans wsdl 28 alberto albertov91 43 software manager data xml directly server srm 202590 black duck inc 20250926 automatically uris 0160 svn svndigger technology detection various fingerprints identifiers wappalyzer 21480 tips tricks token analysis analyze pseudo random tokens those csrf protection tokengen treetools tree carl sampson value generator define field values submitting app added modified enableddisabled deleted formhandler 670 viewstate aspjsf decoder editor calum hutton websockets websocket 33 windows webdriverwindows 163 zest graphical security zaps macro steroids 4890 " }, { "url": "/docs/zap-ownership/",
biz.aQute.bnd.annotation6.4.17.1.0 (Apache-2.0 OR EPL-2.0)
byte-buddy1.17.61.17.8 Apache-2.0
byte-buddy-agent1.14.91.17.7 Apache-2.0
checker-qual3.37.03.43.0 MIT
commonlib1.35.01.38.0
Apache-2.0
commons-codec1.19.0Apache-2.0
commons-collections 3.2.2
commons-collections44.44.5.0 Apache-2.0
commons-csv1.10.01.12.0 Apache-2.0
commons-csv1.12.01.14.1 Apache-2.0
Apache-1.0
commons-io2.16.1Apache-2.0
commons-io 2.18.0
error_prone_annotation2.36.02.42.0 Apache-2.0
error_prone_annotations2.36.02.41.0 Apache-2.0
error_prone_check_api2.36.0error_prone_annotations2.42.0 Apache-2.0
error_prone_core2.36.0error_prone_check_api2.42.0 Apache-2.0
error_prone_type_annotations2.36.0error_prone_core2.42.0 Apache-2.0
failureaccess1.0.11.0.2 Apache-2.0
google-java-format1.19.11.27.0 Apache-2.0
guava32.1.3-jre33.4.0-jre Apache-2.0
guava33.4.8-jre33.5.0-jre Apache-2.0
hamcrest2.23.0 BSD-3-Clause
hamcrest-core2.23.0 BSD-3-Clause
hamcrest-library2.23.0 BSD-3-Clause
Apache-2.0
j2objc-annotations3.1Apache-2.0
jackson-annotations2.19.12.20 Apache-2.0
jackson-bom2.19.12.20.0 Apache-2.0
jackson-core2.19.12.20.0 Apache-2.0
jackson-databind2.19.12.20.0 Apache-2.0
jackson-dataformat-xml2.19.12.20.0 Apache-2.0
jackson-dataformat-yaml2.19.12.20.0 Apache-2.0
jackson-datatype-jdk82.19.12.20.0 Apache-2.0
jackson-datatype-jsr3102.19.12.20.0 Apache-2.0
junit-bom5.10.16.0.0 EPL-2.0
junit-jupiter5.10.16.0.0 EPL-2.0
junit-jupiter-api5.10.16.0.0 EPL-2.0
junit-jupiter-engine5.10.16.0.0 EPL-2.0
junit-jupiter-params5.10.16.0.0 EPL-2.0
junit-platform-commons1.10.16.0.0 EPL-2.0
junit-platform-engine1.10.16.0.0 EPL-2.0
junit-platform-launcher1.10.16.0.0 EPL-2.0
lombok1.18.361.18.40 MIT
mockito-core5.7.05.20.0 MIT
mockito-junit-jupiter5.7.05.20.0 MIT
network0.23.00.24.0
opentelemetry-api1.53.01.55.0 Apache-2.0
opentelemetry-common1.53.01.55.0 Apache-2.0
opentelemetry-context1.53.01.55.0 Apache-2.0
opentelemetry-exporter-logging1.53.01.55.0 Apache-2.0
opentelemetry-sdk1.53.01.55.0 Apache-2.0
opentelemetry-sdk-common1.53.01.55.0 Apache-2.0
opentelemetry-sdk-extension-autoconfigure1.53.01.55.0 Apache-2.0
opentelemetry-sdk-extension-autoconfigure-spi1.53.01.55.0 Apache-2.0
opentelemetry-sdk-logs1.53.01.55.0 Apache-2.0
opentelemetry-sdk-metrics1.53.01.55.0 Apache-2.0
opentelemetry-sdk-trace1.53.01.55.0 Apache-2.0
selenium-api4.35.04.37.0 Apache-2.0
selenium-chrome-driver4.35.04.37.0 Apache-2.0
selenium-chromium-driver4.35.04.37.0 Apache-2.0
selenium-devtools-v1374.35.0selenium-devtools-v1394.37.0 Apache-2.0
selenium-devtools-v1384.35.0selenium-devtools-v1404.37.0 Apache-2.0
selenium-devtools-v1394.35.0selenium-devtools-v1414.37.0 Apache-2.0
selenium-edge-driver4.35.04.37.0 Apache-2.0
selenium-firefox-driver4.35.04.37.0 Apache-2.0
selenium-http4.35.04.37.0 Apache-2.0
selenium-ie-driver4.35.04.37.0 Apache-2.0
selenium-java4.35.04.37.0 Apache-2.0
selenium-json4.35.04.37.0 Apache-2.0
selenium-manager4.35.04.37.0 Apache-2.0
selenium-os4.35.04.37.0 Apache-2.0
selenium-remote-driver4.35.04.37.0 Apache-2.0
selenium-safari-driver4.35.04.37.0 Apache-2.0
selenium-support4.35.04.37.0 Apache-2.0