Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 9 additions & 9 deletions addons/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -456,7 +456,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
<a class="no-border" title="Repository" href="https://github.com/zaproxy/zap-extensions/" target="_blank" rel="noopener noreferrer"><img alt="Repository" src="/img/addons/source.png" /></a>


<a class="no-border" title="Download" href="https://github.com/zaproxy/zap-extensions/releases/download/authhelper-v0.31.0/authhelper-beta-0.31.0.zap" target="_blank" rel="noopener noreferrer"><img alt="Download" src="/img/addons/download.png" /></a>
<a class="no-border" title="Download" href="https://github.com/zaproxy/zap-extensions/releases/download/authhelper-v0.32.0/authhelper-beta-0.32.0.zap" target="_blank" rel="noopener noreferrer"><img alt="Download" src="/img/addons/download.png" /></a>



Expand All @@ -469,7 +469,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
authhelper
</td>
<td align="center">
0.31.0
0.32.0
</td>
<td >
beta
Expand All @@ -478,7 +478,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
ZAP Dev Team
</td>
<td align="center">
2025-11-05
2025-11-07
</td>
</tr>

Expand Down Expand Up @@ -524,7 +524,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
<a class="no-border" title="Repository" href="https://github.com/zaproxy/zap-extensions/" target="_blank" rel="noopener noreferrer"><img alt="Repository" src="/img/addons/source.png" /></a>


<a class="no-border" title="Download" href="https://github.com/zaproxy/zap-extensions/releases/download/automation-v0.55.0/automation-beta-0.55.0.zap" target="_blank" rel="noopener noreferrer"><img alt="Download" src="/img/addons/download.png" /></a>
<a class="no-border" title="Download" href="https://github.com/zaproxy/zap-extensions/releases/download/automation-v0.56.0/automation-beta-0.56.0.zap" target="_blank" rel="noopener noreferrer"><img alt="Download" src="/img/addons/download.png" /></a>



Expand All @@ -537,7 +537,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
automation
</td>
<td align="center">
0.55.0
0.56.0
</td>
<td >
beta
Expand All @@ -546,7 +546,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
ZAP Dev Team
</td>
<td align="center">
2025-11-05
2025-11-07
</td>
</tr>

Expand Down Expand Up @@ -3075,7 +3075,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
<a class="no-border" title="Repository" href="https://github.com/zaproxy/zap-extensions/" target="_blank" rel="noopener noreferrer"><img alt="Repository" src="/img/addons/source.png" /></a>


<a class="no-border" title="Download" href="https://github.com/zaproxy/zap-extensions/releases/download/reports-v0.41.0/reports-release-0.41.0.zap" target="_blank" rel="noopener noreferrer"><img alt="Download" src="/img/addons/download.png" /></a>
<a class="no-border" title="Download" href="https://github.com/zaproxy/zap-extensions/releases/download/reports-v0.42.0/reports-release-0.42.0.zap" target="_blank" rel="noopener noreferrer"><img alt="Download" src="/img/addons/download.png" /></a>



Expand All @@ -3088,7 +3088,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
reports
</td>
<td align="center">
0.41.0
0.42.0
</td>
<td >
release
Expand All @@ -3097,7 +3097,7 @@ <h1 class="text--white">ZAP Marketplace</h1>
ZAP Dev Team
</td>
<td align="center">
2025-09-04
2025-11-07
</td>
</tr>

Expand Down
1 change: 1 addition & 0 deletions docs/desktop/addons/automation-framework/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -1865,6 +1865,7 @@ <h3 id="command-line-options">Command Line Options <a class="header-link" href="
<li>-autogenmin &lt;filename&gt; Generate template automation file with the key parameters.</li>
<li>-autogenmax &lt;filename&gt; Generate template automation file with all parameters.</li>
<li>-autogenconf &lt;filename&gt; Generate template automation file using the current configuration.</li>
<li>-autocheck &lt;source&gt; Check the specified automation plan in the file or from the URL.</li>
</ul>

<h3 id="exit-codes">Exit Codes <a class="header-link" href="#exit-codes"><svg class="fill-current o-60 hover-accent-color-light" height="22px" viewBox="0 0 24 24" width="22px" xmlns="http://www.w3.org/2000/svg"><path d="M0 0h24v24H0z" fill="none"/><path d="M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z" fill="currentColor"/></svg></a></h3>
Expand Down
8 changes: 4 additions & 4 deletions docs/desktop/addons/report-generation/index.xml

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
Expand Up @@ -1908,6 +1908,7 @@ <h3 id="sample">Sample <a class="header-link" href="#sample"><svg class="fill-cu
&#34;instances&#34;:[
{
&#34;uri&#34;: &#34;http://localhost:8080/bodgeit/search.jsp?q=%3C%2Ffont%3E%3CscrIpt%3Ealert%281%29%3B%3C%2FscRipt%3E%3Cfont%3E&#34;,
&#34;nodeName&#34;: &#34;http://localhost:8080/bodgeit/search.jsp (q)&#34;,
&#34;method&#34;: &#34;GET&#34;,
&#34;param&#34;: &#34;q&#34;,
&#34;attack&#34;: &#34;&lt;/font&gt;&lt;scrIpt&gt;alert(1);&lt;/scRipt&gt;&lt;font&gt;&#34;,
Expand All @@ -1920,6 +1921,7 @@ <h3 id="sample">Sample <a class="header-link" href="#sample"><svg class="fill-cu
},
{
&#34;uri&#34;: &#34;http://localhost:8080/bodgeit/contact.jsp&#34;,
&#34;nodeName&#34;: &#34;http://localhost:8080/bodgeit/contact.jsp&#34;,
&#34;method&#34;: &#34;POST&#34;,
&#34;param&#34;: &#34;comments&#34;,
&#34;attack&#34;: &#34;&lt;/td&gt;&lt;scrIpt&gt;alert(1);&lt;/scRipt&gt;&lt;td&gt;&#34;,
Expand All @@ -1932,6 +1934,7 @@ <h3 id="sample">Sample <a class="header-link" href="#sample"><svg class="fill-cu
}
],
&#34;count&#34;: &#34;2&#34;,
&#34;systemic&#34;: false,
&#34;solution&#34;: &#34;&lt;p&gt;Phase: Architecture and Design&lt;/p&gt;&lt;p&gt;Use a vetted library or framework that does not ...&lt;/p&gt;&#34;,
&#34;otherinfo&#34;: &#34;&#34;,
&#34;reference&#34;: &#34;&lt;p&gt;http://projects.webappsec.org/Cross-Site-Scripting&lt;/p&gt;&lt;p&gt;http://cwe.mitre.org/data/definitions/79.html&lt;/p&gt;&#34;,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1884,6 +1884,7 @@ <h3 id="sample">Sample <a class="header-link" href="#sample"><svg class="fill-cu
&#34;instances&#34;:[
{
&#34;uri&#34;: &#34;http://localhost:8080/bodgeit/search.jsp?q=%3C%2Ffont%3E%3CscrIpt%3Ealert%281%29%3B%3C%2FscRipt%3E%3Cfont%3E&#34;,
&#34;nodeName&#34;: &#34;http://localhost:8080/bodgeit/search.jsp (q)&#34;,
&#34;method&#34;: &#34;GET&#34;,
&#34;param&#34;: &#34;q&#34;,
&#34;attack&#34;: &#34;&lt;/font&gt;&lt;scrIpt&gt;alert(1);&lt;/scRipt&gt;&lt;font&gt;&#34;,
Expand All @@ -1892,6 +1893,7 @@ <h3 id="sample">Sample <a class="header-link" href="#sample"><svg class="fill-cu
},
{
&#34;uri&#34;: &#34;http://localhost:8080/bodgeit/contact.jsp&#34;,
&#34;nodeName&#34;: &#34;http://localhost:8080/bodgeit/contact.jsp&#34;,
&#34;method&#34;: &#34;POST&#34;,
&#34;param&#34;: &#34;comments&#34;,
&#34;attack&#34;: &#34;&lt;/td&gt;&lt;scrIpt&gt;alert(1);&lt;/scRipt&gt;&lt;td&gt;&#34;,
Expand All @@ -1900,6 +1902,7 @@ <h3 id="sample">Sample <a class="header-link" href="#sample"><svg class="fill-cu
}
],
&#34;count&#34;: &#34;2&#34;,
&#34;systemic&#34;: false,
&#34;solution&#34;: &#34;&lt;p&gt;Phase: Architecture and Design&lt;/p&gt;&lt;p&gt;Use a vetted library or framework that does not ...&lt;/p&gt;&#34;,
&#34;otherinfo&#34;: &#34;&#34;,
&#34;reference&#34;: &#34;&lt;p&gt;http://projects.webappsec.org/Cross-Site-Scripting&lt;/p&gt;&lt;p&gt;http://cwe.mitre.org/data/definitions/79.html&lt;/p&gt;&#34;,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1919,18 +1919,21 @@ <h4 id="header-risk-confidence">Header <code>Risk (Confidence)</code> <a class="
CSRF has primarily been used to perform an action against a target site using the victim&#39;s privileges, but recent techniques have been discovered to disclose information by gaining access to the response. The risk of information disclosure is dramatically increased when the target site is vulnerable to XSS, because XSS can be used as a platform for CSRF, allowing the attack to operate within the bounds of the same-origin policy.

* URL: http://localhost:8080/bodgeit/advanced.jsp
* Node Name: http://localhost:8080/bodgeit/advanced.jsp
* Method: `GET`
* Parameter: ``
* Attack: ``
* Evidence: `&lt;form id=&#34;advanced&#34; name=&#34;advanced&#34; method=&#34;POST&#34; onsubmit=&#34;return validateForm(this);false;&#34;&gt;`
* Other Info: ``
* URL: http://localhost:8080/bodgeit/advanced.jsp
* Node Name: http://localhost:8080/bodgeit/advanced.jsp
* Method: `GET`
* Parameter: ``
* Attack: ``
* Evidence: `&lt;form id=&#34;query&#34; name=&#34;advanced&#34; method=&#34;POST&#34;&gt;`
* Other Info: ``
* URL: http://localhost:8080/bodgeit/basket.jsp
* Node Name: http://localhost:8080/bodgeit/basket.jsp
* Method: `GET`
* Parameter: ``
* Attack: ``
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1880,6 +1880,7 @@ <h3 id="sample">Sample <a class="header-link" href="#sample"><svg class="fill-cu

&lt;instance&gt;
&lt;uri&gt;http://localhost:8080/bodgeit/js&lt;/uri&gt;
&lt;nodeName&gt;http://localhost:8080/bodgeit/js&lt;/nodeName&gt;
&lt;method&gt;GET&lt;/method&gt;
&lt;param&gt;&lt;/param&gt;
&lt;attack&gt;&lt;/attack&gt;
Expand Down Expand Up @@ -1913,6 +1914,7 @@ <h3 id="sample">Sample <a class="header-link" href="#sample"><svg class="fill-cu

&lt;instance&gt;
&lt;uri&gt;http://localhost:8080/bodgeit/js/util.js&lt;/uri&gt;
&lt;nodeName&gt;http://localhost:8080/bodgeit/js/util.js&lt;/nodeName&gt;
&lt;method&gt;GET&lt;/method&gt;
&lt;param&gt;&lt;/param&gt;
&lt;attack&gt;&lt;/attack&gt;
Expand Down Expand Up @@ -2009,6 +2011,7 @@ <h3 id="sample">Sample <a class="header-link" href="#sample"><svg class="fill-cu

&lt;/instances&gt;
&lt;count&gt;3&lt;/count&gt;
&lt;systemic&gt;false&lt;/systemic&gt;
&lt;solution&gt;&lt;/solution&gt;
&lt;otherinfo&gt;NOTE: Because of its name this cookie may be important, but dropping it appears to have no effect: [JSESSIONID]
Cookies that don&amp;apos;t have expected effects can reveal flaws in application logic. In the worst case, this can reveal where authentication via cookie token(s) is not actually enforced.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1878,9 +1878,9 @@ <h3 id="sample">Sample <a class="header-link" href="#sample"><svg class="fill-cu
&lt;confidencedesc&gt;Medium&lt;/confidencedesc&gt;
&lt;desc&gt;&lt;p&gt;A cross-site request forgery is an attack that involves forcing a victim to send an HTTP request to a target destination without their knowledge...&lt;/desc&gt;
&lt;instances&gt;

&lt;instance&gt;
&lt;uri&gt;http://localhost:8080/bodgeit/advanced.jsp&lt;/uri&gt;
&lt;nodeName&gt;http://localhost:8080/bodgeit/advanced.jsp&lt;/nodeName&gt;
&lt;method&gt;GET&lt;/method&gt;
&lt;param&gt;&lt;/param&gt;
&lt;attack&gt;&lt;/attack&gt;
Expand All @@ -1890,6 +1890,7 @@ <h3 id="sample">Sample <a class="header-link" href="#sample"><svg class="fill-cu

&lt;instance&gt;
&lt;uri&gt;http://localhost:8080/bodgeit/advanced.jsp&lt;/uri&gt;
&lt;nodeName&gt;http://localhost:8080/bodgeit/advanced.jsp&lt;/nodeName&gt;
&lt;method&gt;GET&lt;/method&gt;
&lt;param&gt;&lt;/param&gt;
&lt;attack&gt;&lt;/attack&gt;
Expand All @@ -1899,12 +1900,17 @@ <h3 id="sample">Sample <a class="header-link" href="#sample"><svg class="fill-cu

&lt;instance&gt;
&lt;uri&gt;http://localhost:8080/bodgeit/basket.jsp&lt;/uri&gt;
&lt;nodeName&gt;http://localhost:8080/bodgeit/basket.jsp&lt;/nodeName&gt;
&lt;method&gt;GET&lt;/method&gt;
&lt;param&gt;&lt;/param&gt;
&lt;attack&gt;&lt;/attack&gt;
&lt;evidence&gt;&lt;form action=&#34;basket.jsp&#34; method=&#34;post&#34;&gt;&lt;/evidence&gt;
&lt;otherinfo&gt;&lt;/otherinfo&gt;
&lt;/instance&gt;
&lt;count&gt;2&lt;/count&gt;
&lt;systemic&gt;false&lt;/systemic&gt;
&lt;solution&gt;The solution&lt;/solution&gt;
&lt;otherinfo&gt;The other info&lt;/otherinfo&gt;
</code></pre>
</div>
</div>
Expand Down
6 changes: 3 additions & 3 deletions docs/sbom/authhelper/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -122,9 +122,9 @@ <h1 class="text--white">Authentication Helper Add-on SBOM</h1>
<a href="/docs/sbom/authhelper">Authentication Helper</a>
</header>
<br>
<p>This page contains a list of all the libraries involved in building version <code>0.31.0</code> of the
<p>This page contains a list of all the libraries involved in building version <code>0.32.0</code> of the
"Authentication Helper" add-on.
<p>You may download the full <a href="https://github.com/zaproxy/zap-extensions/releases/download/authhelper-v0.31.0/bom.json">Software Bill Of Materials (SBOM) JSON file</a>
<p>You may download the full <a href="https://github.com/zaproxy/zap-extensions/releases/download/authhelper-v0.32.0/bom.json">Software Bill Of Materials (SBOM) JSON file</a>
for this add-on.
<div class="flex">
<table>
Expand Down Expand Up @@ -203,7 +203,7 @@ <h1 class="text--white">Authentication Helper Add-on SBOM</h1>

<tr>
<td>automation</td>
<td align="center">0.55.0</td>
<td align="center">0.56.0</td>
<td></td>
</tr>

Expand Down
4 changes: 2 additions & 2 deletions docs/sbom/automation/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -122,9 +122,9 @@ <h1 class="text--white">Automation Framework Add-on SBOM</h1>
<a href="/docs/sbom/automation">Automation Framework</a>
</header>
<br>
<p>This page contains a list of all the libraries involved in building version <code>0.55.0</code> of the
<p>This page contains a list of all the libraries involved in building version <code>0.56.0</code> of the
"Automation Framework" add-on.
<p>You may download the full <a href="https://github.com/zaproxy/zap-extensions/releases/download/automation-v0.55.0/bom.json">Software Bill Of Materials (SBOM) JSON file</a>
<p>You may download the full <a href="https://github.com/zaproxy/zap-extensions/releases/download/automation-v0.56.0/bom.json">Software Bill Of Materials (SBOM) JSON file</a>
for this add-on.
<div class="flex">
<table>
Expand Down
2 changes: 1 addition & 1 deletion docs/sbom/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -548,7 +548,7 @@ <h1 class="text--white">Software Bill of Materials</h1>
<a href="/docs/sbom/reports/">Report Generation Add-on SBOM</a>
</td>
<td>
145
163
</td>
</tr>

Expand Down
Loading