Firefox Browser Add-ons
  • Extensions
  • Themes
    • for Firefox
    • Dictionaries & Language Packs
    • Other Browser Sites
    • Add-ons for Android
Log in
Preview of XSSassin - Payload Injector

XSSassin - Payload Injector by yesmayank

Security testing: inject payloads into input fields. XSS, SQLi, HTML injection and more.

Available on Firefox for Android™Available on Firefox for Android™
0 (0 reviews)0 (0 reviews)
Download Firefox and get the extension
Download file

Extension Metadata

Screenshots
XSSassin - Web Security Payload Injector
About this extension
Security testing: inject payloads into input fields. XSS, SQLi, HTML injection and more.

XSSassin: The Ultimate Payload Injector for Pentesters & Bug Bounty Hunters

XSSassin is an advanced security testing extension designed specifically for ethical hackers, penetration testers, and security-conscious developers. Seamlessly inject common attack payloads directly into web page input fields to test for vulnerabilities like XSS, SQLi, and more—all with a single click!

🚀 CORE FEATURES:

One-Click Injection: Hover over any text field, textarea, or contenteditable area to instantly reveal quick-inject buttons.

Massive Payload Library: Built-in payloads for Cross-Site Scripting (XSS), SQL Injection (SQLi), HTML Injection, NoSQL, LDAP, OS Command Injection, XPath, SSTI, CRLF, and XXE.

Custom Payloads: Tailor your pentesting arsenal by adding your own custom payloads in the extension options.

Auto-Fill All: Hunting for bugs? Fill every input on a target page with your default or a random payload simultaneously.

Per-Site Toggling: Easily enable or disable the extension on specific domains to keep your regular browsing clean.

🛠 WHO IS THIS FOR?

Bug Bounty Hunters looking to speed up manual testing.

Penetration Testers conducting web application security assessments.

QA Engineers and Developers ensuring their forms are sanitized and secure.

⚠️ IMPORTANT / DISCLAIMER:
XSSassin is built strictly for educational purposes and authorized ethical hacking. Only use this tool on applications you own or have explicit permission to test. The developers assume no liability for misuse.
Rated 0 by 0 reviewers
Log in to rate this extension
There are no ratings yet

Star rating saved

5
0
4
0
3
0
2
0
1
0
No reviews yet
Permissions and data

Required permissions:

  • Access browser tabs
  • Access your data for all websites

Optional permissions:

  • Access your data for all websites

Data collection:

  • The developer says this extension doesn't require data collection.
Learn more
More information
Add-on Links
  • Support Email
Version
1.3.2
Size
450.13 KB
Last updated
9 days ago (Apr 22, 2026)
Related Categories
  • Web Development
  • Privacy & Security
  • Search Tools
License
Apache License 2.0
Version History
  • See all versions
Tags
  • privacy
  • security
Add to collection
Report this add-on
Go to Mozilla's homepage

Add-ons

  • About
  • Firefox Add-ons Blog
  • Extension Workshop
  • Developer Hub
  • Developer Policies
  • Community Blog
  • Forum
  • Report a bug
  • Review Guide

Browsers

  • Desktop
  • Mobile
  • Enterprise

Products

  • Browsers
  • VPN
  • Relay
  • Monitor
  • Pocket
  • Bluesky (@firefox.com)
  • Instagram (Firefox)
  • YouTube (firefoxchannel)
  • Privacy
  • Cookies
  • Legal

Except where otherwise noted, content on this site is licensed under the Creative Commons Attribution Share-Alike License v3.0 or any later version. Android is a trademark of Google LLC.