Application-layer vulnerability cheatsheets — detection, exploitation, bypass, and remediation guidance for each class. Sources cite OWASP WSTG, PortSwigger Academy, OWASP Cheat Sheet Series, PayloadsAllTheThings, and HackTricks.
Phase 9j adds a web/frameworks/ subdirectory with Spring Boot Actuator, WordPress, Jenkins, GitLab, Laravel, Django admin cheatsheets.
- OWASP Web Security Testing Guide v4.2: https://owasp.org/www-project-web-security-testing-guide/v42/
- OWASP Top 10 (2021): https://owasp.org/Top10/
- PortSwigger Web Security Academy: https://portswigger.net/web-security
- OWASP Cheat Sheet Series: https://cheatsheetseries.owasp.org/
- HackTricks Pentesting Web: https://book.hacktricks.wiki/en/pentesting-web/web-vulnerabilities-methodology.html