What problem does it solve?
Security teams and researchers need a consolidated reference of common web2 vulnerability classes to quickly identify patterns, test ideas, and prioritize bug-bounty submissions. The vuln-matrix provides structured root causes, detection patterns, bypass techniques, exploit references, and paid real-world examples across 20 classes.
Core Features & Use Cases
- Comprehensive coverage of 20 web2 bug classes including IDOR, broken auth, XSS, SSRF, SQLi, OAuth/OIDC, file upload bypasses, GraphQL, LLM/AI, API misconfig, ATO taxonomy, SSTI, subdomain takeover, cloud misconfigurations, HTTP request smuggling, cache poisoning, MFA bypass, and SAML attacks.
- Detection patterns, bypass tables, and practical test scenarios with references to real-world paid findings.
- Use in bug-bounty hunting, security research, and training to quickly map targets to applicable vulnerability classes and testing steps.
Quick Start
Read and study the matrix to understand each class's root causes, patterns, and typical exploit techniques, then apply the patterns to your testing workflow.