Wordlists

Curated collection of wordlists for penetration testing, security research, and ethical hacking

Sponsored by You, contact hello@pentestlist.com for options

Vulnerability Fuzzing Wordlists

Payload lists for testing XSS, SQLi, LFI, and other vulnerabilities

Content-Type Payloads

A short list of Content-Types for header issue discovery.

XXE Payloads

A short list of payloads for XXE discovery.

LFI Payloads

A short list of payloads for LFI discovery.

SQLi Payloads

A short list of payloads for SQLi discovery.

XSS Payloads

A short list of payloads for XSS discovery.

Directory and Path Fuzzing Wordlists

Directory, file path, subdomain, and parameter lists for web content discovery

Subdomains Discovery - Large List

A list of 9996122 lines to use for more complete subdomain discovery.

Subdomains Discovery - Medium List

A list of 2441323 lines to use for fast subdomain discovery.

Parameter Discovery

A list of 307740 lines to use for parameter discovery.

API Route Discovery

A list of 290546 lines to use for API route discovery.

Web Content Discovery - Large List

A list of 692777 lines to use for more complete content discovery.

Web Content Discovery - Small List

A list of 128347 lines to use for fast content discovery.

Credential Brute Forcing Wordlists

Password lists and rules for authentication testing and credential attacks

OneRuleToRuleThemStill Rule

A rule created using the top 25% performing rules

Best66 Rule

The best rule for quick password cracking.

d3adhob0 Rule

Password cracking rules for Hashcat based on statistics and industry patterns

OneWordlistToListThemAll Passwords

The only password list you will ever need. Use this with the rules below for maximum password cracking potential.