Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 9 additions & 9 deletions addons/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -827,7 +827,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
<a class="no-border" title="Repository" href="https://github.com/zaproxy/zap-extensions/" target="_blank" rel="noopener noreferrer"><img alt="Repository" src="/img/addons/source.png" /></a>


<a class="no-border" title="Download" href="https://github.com/zaproxy/zap-extensions/releases/download/commonlib-v1.37.0/commonlib-release-1.37.0.zap" target="_blank" rel="noopener noreferrer"><img alt="Download" src="/img/addons/download.png" /></a>
<a class="no-border" title="Download" href="https://github.com/zaproxy/zap-extensions/releases/download/commonlib-v1.38.0/commonlib-release-1.38.0.zap" target="_blank" rel="noopener noreferrer"><img alt="Download" src="/img/addons/download.png" /></a>



Expand All @@ -840,7 +840,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
commonlib
</td>
<td align="center">
1.37.0
1.38.0
</td>
<td >
release
Expand All @@ -849,7 +849,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
ZAP Dev Team
</td>
<td align="center">
2025-10-07
2025-10-21
</td>
</tr>

Expand Down Expand Up @@ -2731,7 +2731,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
<a class="no-border" title="Repository" href="https://github.com/zaproxy/zap-extensions/" target="_blank" rel="noopener noreferrer"><img alt="Repository" src="/img/addons/source.png" /></a>


<a class="no-border" title="Download" href="https://github.com/zaproxy/zap-extensions/releases/download/pscanrules-v67/pscanrules-release-67.zap" target="_blank" rel="noopener noreferrer"><img alt="Download" src="/img/addons/download.png" /></a>
<a class="no-border" title="Download" href="https://github.com/zaproxy/zap-extensions/releases/download/pscanrules-v68/pscanrules-release-68.zap" target="_blank" rel="noopener noreferrer"><img alt="Download" src="/img/addons/download.png" /></a>



Expand All @@ -2744,7 +2744,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
pscanrules
</td>
<td align="center">
67
68
</td>
<td >
release
Expand All @@ -2753,7 +2753,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
ZAP Dev Team
</td>
<td align="center">
2025-09-18
2025-10-21
</td>
</tr>

Expand Down Expand Up @@ -3421,7 +3421,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
<a class="no-border" title="Repository" href="https://github.com/zaproxy/zap-extensions/" target="_blank" rel="noopener noreferrer"><img alt="Repository" src="/img/addons/source.png" /></a>


<a class="no-border" title="Download" href="https://github.com/zaproxy/zap-extensions/releases/download/selenium-v15.40.0/selenium-release-15.40.0.zap" target="_blank" rel="noopener noreferrer"><img alt="Download" src="/img/addons/download.png" /></a>
<a class="no-border" title="Download" href="https://github.com/zaproxy/zap-extensions/releases/download/selenium-v15.41.0/selenium-release-15.41.0.zap" target="_blank" rel="noopener noreferrer"><img alt="Download" src="/img/addons/download.png" /></a>



Expand All @@ -3434,7 +3434,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
selenium
</td>
<td align="center">
15.40.0
15.41.0
</td>
<td >
release
Expand All @@ -3443,7 +3443,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
ZAP Dev Team
</td>
<td align="center">
2025-09-02
2025-10-21
</td>
</tr>

Expand Down
3 changes: 3 additions & 0 deletions docs/desktop/addons/common-library/alerttags/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -1870,6 +1870,9 @@ <h2 id="compliance">Compliance Tags <a class="header-link" href="#compliance"><s
<h2 id="cve-tags">CVE Tags <a class="header-link" href="#cve-tags"><svg class="fill-current o-60 hover-accent-color-light" height="22px" viewBox="0 0 24 24" width="22px" xmlns="http://www.w3.org/2000/svg"><path d="M0 0h24v24H0z" fill="none"/><path d="M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z" fill="currentColor"/></svg></a></h2>
<p>Any alert that involves a specific CVE will (generally) also have a tag for that specific CVE identifier with a value that links to Mitre&rsquo;s National Vulnerability Database (NVD).</p>

<h2 id="systemic">SYSTEMIC Tag <a class="header-link" href="#systemic"><svg class="fill-current o-60 hover-accent-color-light" height="22px" viewBox="0 0 24 24" width="22px" xmlns="http://www.w3.org/2000/svg"><path d="M0 0h24v24H0z" fill="none"/><path d="M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z" fill="currentColor"/></svg></a></h2>
<p>The SYSTEMIC tag is used to flag alerts that are often &ldquo;Site wide&rdquo;. These include most rules related to headers. From ZAP 2.17.0 only a limited number of systemic alerts will be included in the Desktop UI and reports by default.</p>

<h2 id="policy-tags">Policy Tags <a class="header-link" href="#policy-tags"><svg class="fill-current o-60 hover-accent-color-light" height="22px" viewBox="0 0 24 24" width="22px" xmlns="http://www.w3.org/2000/svg"><path d="M0 0h24v24H0z" fill="none"/><path d="M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z" fill="currentColor"/></svg></a></h2>
<p>The add-on also provides a set of Alert Tags which associate various rule types or focus areas to scan policies, see the <a href="/docs/desktop/addons/scan-policies/">Scan
Policies add-on help</a> for further details.</p>
Expand Down
6 changes: 3 additions & 3 deletions docs/desktop/addons/passive-scan-rules/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -2096,14 +2096,14 @@ <h2 id="id-10028">Off-site Redirect <a class="header-link" href="#id-10028"><svg

<h2 id="id-10062">PII Disclosure <a class="header-link" href="#id-10062"><svg class="fill-current o-60 hover-accent-color-light" height="22px" viewBox="0 0 24 24" width="22px" xmlns="http://www.w3.org/2000/svg"><path d="M0 0h24v24H0z" fill="none"/><path d="M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z" fill="currentColor"/></svg></a></h2>
<p>PII is information like credit card number, SSN etc. This check currently reports only numbers which match credit card numbers and pass Luhn checksum, which gives high confidence, that this is a credit card number.<br>
At MEDIUM and HIGH threshold it attempts to use three characters of context on each side of potential matches to exclude matches within decimal like content. At LOW threshold, alerts will be raised for such matches.</p>
At MEDIUM and HIGH threshold it attempts to use three characters of context on each side of potential matches to exclude matches within decimal like content or content which includes underscores. At LOW threshold, alerts will be raised for such matches.</p>
<p>At MEDIUM and HIGH threshold, the following content types are evaluated:</p>
<ul>
<li>HTML</li>
<li>HTML (visible text and script blocks)</li>
<li>JSON</li>
<li>XML</li>
</ul>
<p>Image and CSS files are always ignored. Every other content type is evaluated at LOW threshold.</p>
<p>Image and CSS files are always ignored. Every other content type is evaluated at LOW threshold. Additionally at LOW threshold the entire HTML response is evaluated.</p>
<p>Note: In the case of suspected credit card values, the potential credit card numbers are looked up against a Bank Identification Number List
(BINList). If a match is found the alert is raised at High confidence and additional details are added to the &lsquo;Other Information&rsquo; field in the
alert, otherwise the alerts will have Medium confidence.
Expand Down
Loading