πŸ“¦Default Profiles

Burp Bounty Pro ships with 254 pre-configured profiles covering CVE exploits, common vulnerabilities, technology detection, and sensitive data exposure.

πŸ“Š Summary

Category
Count

🎯 Active Scanning Profiles

101

πŸ“© Passive Response Profiles

95

πŸ“¨ Passive Request Profiles

58

Total

254

⚠️ Severity Distribution

Severity
Count

πŸ”΄ High

68

🟠 Medium

29

🟑 Low

8

πŸ”΅ Information

149

🎯 Active Profiles by Category

πŸ› CVE Exploits

Profile
Severity
Tags

CVE-2017-9506_Jira_SSRF

Medium

CVEs

CVE-2018-1271_Spring_MVC_Path_Traversal

High

CVEs

CVE-2018-13379_FortiOS_Creds_Disclosure

High

CVEs

CVE-2019-11510_Pulse_Secure

High

CVEs

CVE-2019-11580_Atlassian_Crowd_RCE

High

CVEs

CVE-2019-1653_Cisco_Wan_VPN_disclosure

High

CVEs

CVE-2019-19781_Citrix_ADC_Directory_Traversal

Medium

CVEs

CVE-2019-3799_Spring_Cloud_Path_Traversal

High

CVEs

CVE-2019-5418_Ruby on Rails

High

CVEs

CVE-2019-5418_Ruby on Rails - WAF bypass

High

CVEs

CVE-2019-8442_Jira_Path_Traversal

Medium

CVEs

CVE-2019-8449_Jira_Unauthenticated_Sensitive_Info

Medium

CVEs

CVE-2020-11738_Wordpress_Duplicator_Plugin_LFI

High

CVEs, Wordpress

CVE-2020-13167_Netsweeper_code_injection

High

CVEs

CVE-2020-13379_Grafana_SSRF

High

CVEs

CVE-2020-14179_Jira_Info_Exposure

Medium

CVEs

CVE-2020-14181_Jira_User_Enum

Medium

CVEs

CVE-2020-14815_XSS

Medium

XSS

CVE-2020-15129_Traefik_Open_Redirect

Medium

CVEs

CVE-2020-17506_Artica_Web_Proxy_Auth_Bypass

High

CVEs

CVE-2020-24312_File_Manager_Wordpress_Backups

High

CVEs, Wordpress

CVE-2020-2551_Oracle_WebLogic

High

CVEs

CVE-2020-3452_Cisco_ASA_LFI

Medium

CVEs

CVE-2020-5410_Path_Traversal_Spring_Cloud

Medium

CVEs

CVE-2020-5412_Spring_Cloud_Netflix

High

CVEs

CVE-2020-5777_MAMGI_Auth_Bypass

Medium

CVEs

CVE-2020-5902_F5-BigIP

High

CVEs

CVE-2020-8209_Citrix_XenMobile_PathTraversal

High

CVEs

CVE-2020-8982_Citrix_ShareFile_File_Read

Medium

CVEs

CVE-2020-9484_Tomcat_Groovy

High

CVEs

CVE-2021-26086_PathTraversal_Atlassian_Jira

Medium

CVEs

CVE-2021-40438_Apache_mod_proxy_SSRF

High

CVEs

CVE-2021-40539_Zoho_ManageEngine_ADSelfService

High

CVEs

CVE-2021-43798_Grafana_LFI

High

CVEs

CVE-2021-44228_RCE_Log4j

High

RCE, CVEs

CVE-2021-44228_RCE_Log4j_GETPOST

High

RCE, CVEs

CVE-2021-44228_RCE_Log4j_urlEncode

High

RCE, CVEs

CVE-2022-1388_F5_Big_IP_RCE

High

CVEs, RCE

CVE-2022-26134_Confluence_RCE

High

CVEs, RCE

CVE-2022-31474_BackupBuddy_LFI

Medium

CVEs

CVE-2022-32276_Grafana_8.4.3

Medium

CVEs

CVE-2022-32276_Grafana_8.4.3_poc2

Medium

CVEs

CVE-2022-42889_Text4Shell

High

CVEs

CVE-2023-24488_Citrix_XSS

Medium

All

CVE-2025-55182_React2Shell_RCE

High

RCE, CVEs, React/Next.js

CVE-2025-55182_React2Shell_RCE_OOB

High

RCE, React/Next.js, CVEs

CVE-2025-55182_React2Shell_RCE_Windows

High

RCE, CVEs, React/Next.js

CVE-2025-68613_n8n_Vulnerable_Version

High

CVEs, RCE, n8n

πŸ’‰ XSS (Cross-Site Scripting)

Profile
Severity
Tags

Blind_XSS

Medium

XSS, Blind XSS

Openredirect_to_XSS

Medium

XSS

Test_XSS_discover

Medium

XSS

XSS

Information

XSS

XSS_DOM_Context

Information

XSS, DOM_Context

XSS_GETPOST

Medium

XSS

XSS_HTML_Attribute_Context

Information

XSS, HTML_Attribute

XSS_HTML_Comment_Context

Information

XSS, HTML_Comment

XSS_HTML_Tag_Context

Information

XSS, HTML_Tag

XSS_HtmlUrlEncode

Information

XSS

XSS_JavaScript_Context

Information

XSS, JavaScript_Context

XSS_URLEncode

Information

XSS

XSS_URL_Context

Information

XSS, URL_Context

πŸ—„οΈ SQL Injection

Profile
Severity
Tags

SQLi

High

SQLi

SQLi_Collaborator

High

SQLi

SQLi_ContentLength

High

SQLi, SQLi_ContentLength

SQLi_StausCode

High

SQLi, SQLi_StatusCode

SQLi_Timebased

High

SQLi, SQLi_TimeBased

SQLi_Timebased_Encoded_KeyCharacter

High

SQLi, SQLi_TimeBased

SQLi_Timebased_Encoded_Space

High

SQLi, SQLi_TimeBased

⚑ RCE (Remote Code Execution)

Profile
Severity
Tags

Blind_RCE_Linux

High

RCE

Blind_RCE_Windows

High

RCE

Echo_RCE

High

RCE

Expect_RCE

High

RCE

PHP_RCE

High

RCE

RCE_Linux

High

RCE

RCE_Windows

High

RCE

🌐 SSRF (Server-Side Request Forgery)

Profile
Severity
Tags

OpenRedirect_SSRF

High

SSRF, Open Redirect

OpenRedirect_SSRF_Collaborator

Medium

SSRF, Open Redirect

OpenRedirect_SSRF_Collaborator_HTTP0_9

Medium

All

OpenRedirect_SSRF_Collaborator_HTTP1_0

Medium

All

SSRF-Collaborator

Medium

SSRF

SSRF-URLScheme

High

SSRF

SSRF_Collaborator_HTTP0_9

Medium

SSRF

SSRF_Collaborator_HTTP1_0

Medium

SSRF

πŸ”„ Open Redirect

Profile
Severity
Tags

OpenRedirect

Medium

Open Redirect

OpenRedirect-ParameterPollution

Medium

Open Redirect

OpenRedirect-ParameterPollution_Path

Medium

Open Redirect

OpenRedirect_to_Account_Takeover

High

All

πŸ“„ XXE (XML External Entity)

Profile
Severity
Tags

Blind_XXE

High

XXE

XXE_Linux

High

XXE

XXE_Windows

High

XXE

πŸ“‚ Path Traversal

Profile
Severity
Tags

PathTraversal_Linux

High

Path Traversal

PathTraversal_Windows

High

Path Traversal

πŸ”§ Other Active Profiles

Profile
Severity
Tags

CORS Misconfiguration

Low

CORS

CRLF

Medium

CRLF

CouchDB_Admin_Exposure

Medium

CVEs

DWR_enpoints

Information

DRWuzz

Drupal_User_Enum

Medium

Drupal

Drupal_User_Enum_Redirect

Medium

Drupal

Fuzzing_directories

Information

Fuzzing Files

GitFinder

Low

Fuzzing Files

GraphQL Alias Overloading

Medium

GraphQL

GraphQL Batching

Medium

GraphQL

GraphQL Circular Queries

Medium

GraphQL

GraphQL Directives Overloading

Medium

GraphQL

GraphQL Field Duplication

Medium

GraphQL

Graphql Introspection

Low

Introspection

Host_Header_Injection

High

All

Java_De-Serialization

Information

All

Jira_unauthenticated_Info

Medium

CVEs

Kubernetes_API_Exposed

Medium

All

Open Firebase Database

High

All

Password-Reset-Headers

High

Forgot Password

Password-Reset-Params

High

Forgot Password

Password-Reset-URL

High

Forgot Password

SSTI

High

SSTI

SVNFinder

Low

Fuzzing Files

Source_code

Information

All

Spring_Boot_Actuators

High

Spring

Swagger-Finder

Information

Fuzzing Files

Symfony_Debug

Medium

All

Wordpress_Config_Accessible

High

Wordpress

Wordpress_Path_Traversal

High

Wordpress

Wordpress_XMLRPC_ListMethods

Low

Wordpress

Wordpress_XMLRPC_Pingback

Low

Wordpress

Wordpress_directory_listing

Low

Wordpress

Wordpress_user_enum_json

Low

Wordpress

Wordpress_user_enum_oembed

Low

Wordpress

Woody_Wordpress_RCE

Medium

Wordpress

X-Headers-Collaborator

Medium

X-Headers-Collab

easy_wp_smtp_listing_enabled

High

Wordpress

solarwinds_default_admin

High

All

wordpress_users_enum_yoastseo

Low

Wordpress


πŸ“© Passive Response Profiles (95)

These profiles analyze HTTP responses for security issues, sensitive data, and technology indicators.

Profile
Severity
Description

AWS_Access_Key_ID

Information

πŸ”‘ Detects AWS Access Key IDs

AWS_Client_Secret

Information

πŸ”‘ Detects AWS Client Secrets

AWS_Creds_File

Information

πŸ“ Detects AWS credentials file references

AWS_EC2_Url

Information

☁️ Detects AWS EC2 metadata URLs

AWS_Region

Information

☁️ Detects AWS region identifiers

AccessToken

Information

πŸ”‘ Detects access tokens in responses

AmazonAWS

Information

☁️ Detects Amazon AWS URLs

Amazon_AWS_Url

Information

☁️ Detects Amazon AWS endpoint URLs

Amazon_MWS_Auth_Token

Information

πŸ”‘ Detects Amazon MWS authentication tokens

Android_WebView_JS

Information

πŸ“± Detects Android WebView JavaScript interfaces

ApiKeyResponse

Information

πŸ”‘ Detects API keys in responses

Artica_Web

Information

πŸ–₯️ Detects Artica Web Proxy

Artifactory_API_Token

Information

πŸ”‘ Detects JFrog Artifactory API tokens

Authorization_Bearer

Information

πŸ”‘ Detects Bearer tokens in responses

Azure_Blob_Discovered

Information

☁️ Detects Azure Blob storage URLs

Basic_Auth_Credentials

Information

πŸ”‘ Detects Basic Auth credentials

Bitcoin_Address

Information

πŸ’° Detects Bitcoin addresses

CDN_Detected

Information

🌐 Detects CDN usage

CMS_Found

Information

πŸ–₯️ Detects CMS platforms

Cache-Control

Information

πŸ›‘οΈ Analyzes Cache-Control headers

Cisco_ASA_Device_Found

Low

πŸ–₯️ Detects Cisco ASA devices

Citrix_Detection

Information

πŸ–₯️ Detects Citrix products

Content-Security-Policy

Information

πŸ›‘οΈ Analyzes CSP headers

CookieFlag-HttpOnly

Low

πŸͺ Checks for missing HttpOnly flag

CookieFlag-SameSite

Information

πŸͺ Checks for SameSite cookie attribute

CookieFlag-Secure

Low

πŸͺ Checks for missing Secure flag

CouchDB_Response

Information

πŸ—„οΈ Detects CouchDB responses

DWREndpoints

Information

πŸ”— Detects DWR (Direct Web Remoting) endpoints

Debug Pages

Information

⚠️ Detects debug/error pages

Debug_variables

Information

⚠️ Detects debug variables in responses

DefaultRDP

Information

πŸ–₯️ Detects default RDP configurations

DigitalOcean_Space_Discovered

Information

☁️ Detects DigitalOcean Spaces

DirectoryListing

Information

πŸ“‚ Detects directory listing

Docker_API_Response

Information

🐳 Detects Docker API responses

DomainTakeOver_Strings

Information

🌐 Detects domain takeover indicators

Drupal_Response

Information

πŸ–₯️ Detects Drupal CMS

EndpointsExtractor

Information

πŸ”— Extracts API endpoints from JS

Env_Vars

Information

⚠️ Detects environment variables

Facebook_Client_ID

Information

πŸ”‘ Detects Facebook Client IDs

Facebook_OAuth

Information

πŸ”‘ Detects Facebook OAuth tokens

Fortinet_Panel

Information

πŸ›‘οΈ Detects Fortinet admin panels

GCP_Service_Account

Information

☁️ Detects GCP service accounts

GCP_Urls

Information

☁️ Detects Google Cloud Platform URLs

Gmail_Oauth_2.0

Information

πŸ”‘ Detects Gmail OAuth tokens

Google_Cloud_Buckets

Information

☁️ Detects Google Cloud Storage buckets

Hidden Parameters

Information

πŸ” Detects hidden form parameters

Interesting_Keyworks

Information

πŸ” Detects interesting keywords

JS_Variables

Information

πŸ“ Extracts JavaScript variables

Jenkins_Response

Information

πŸ–₯️ Detects Jenkins CI

Joomla detection

Information

πŸ–₯️ Detects Joomla CMS

Joomla-CVE-2015-7297

High

πŸ› Detects Joomla CVE-2015-7297

Kubernetes_Response

Information

☸️ Detects Kubernetes

LinkedIn_Secret

Information

πŸ”‘ Detects LinkedIn API secrets

MAC_Address

Information

πŸ”— Detects MAC addresses

MAGMI_Response

Information

πŸ–₯️ Detects MAGMI (Magento Mass Importer)

Netsweeper_Response

Information

πŸ–₯️ Detects Netsweeper

NoSQL_Session_Token

Information

πŸ”‘ Detects NoSQL session tokens

NuGet_Api_Key

Information

πŸ”‘ Detects NuGet API keys

Octopus_API_Key

Information

πŸ”‘ Detects Octopus Deploy API keys

Outlook_Team

Information

πŸ“§ Detects Outlook/Teams info

Paypal_Braintree_access_token

Information

πŸ”‘ Detects PayPal Braintree tokens

Picatic_API_Key

Information

πŸ”‘ Detects Picatic API keys

Private_SSH_Key

Information

πŸ”‘ Detects private SSH keys

Reflected_values_greater_than_three_characters

Information

πŸͺž Detects reflected values

SQL_Message_Detected

Information

πŸ—„οΈ Detects SQL error messages

ServerBannerResponse

Information

πŸ–₯️ Detects server banners

Software_Version

Information

πŸ“Š Detects software version strings

Solarwinds_Orion_Response

Information

πŸ–₯️ Detects SolarWinds Orion

SonarQube_API_Key_Docs

Information

πŸ”‘ Detects SonarQube API keys

StackHawk_API_Key

Information

πŸ”‘ Detects StackHawk API keys

Strict-Transport-Security

Information

πŸ›‘οΈ Checks HSTS header

Subdomain_takeover

Low

🌐 Detects subdomain takeover indicators

Swagger_found

Information

πŸ“„ Detects Swagger/OpenAPI docs

Symfony_Response

Information

πŸ–₯️ Detects Symfony framework

Tomcat_Response_Detection

Information

πŸ–₯️ Detects Apache Tomcat

Traefik_Response

Information

πŸ–₯️ Detects Traefik proxy

WAF_Found

Information

πŸ›‘οΈ Detects Web Application Firewalls

WP_Config

Information

⚠️ Detects WordPress config exposure

Wordpress detection

Information

πŸ–₯️ Detects WordPress CMS

Wordpress-SensitiveDirectories

Information

πŸ“‚ Detects sensitive WP directories

X-Content-Type-Options

Information

πŸ›‘οΈ Checks X-Content-Type-Options

X-Frame-Options

Information

πŸ›‘οΈ Checks X-Frame-Options

vBulletin_Response

Information

πŸ–₯️ Detects vBulletin forum

Docker_API_Response

Information

🐳 Detects Docker API


πŸ“¨ Passive Request Profiles (58)

These profiles analyze HTTP requests to detect interesting parameters, endpoints, and technology indicators.

Profile
Severity
Description

Action_parameters

Information

βš™οΈ Detects action-related parameters

All_Requests_And_Parameters

Information

🌐 Matches all requests (for bulk rules)

AmazonAWSRequest

Information

☁️ Detects AWS API requests

ApiKeyRequest

Information

πŸ”‘ Detects API key parameters in requests

Api_path

Information

πŸ”— Detects API path patterns

Artica_Web_Request

Information

πŸ–₯️ Detects Artica Web requests

AuthorizationBearerToken

Information

πŸ”‘ Detects Bearer tokens in requests

Cisco_Request_Detected

Information

πŸ–₯️ Detects Cisco-related requests

CouchDB_Request

Information

πŸ—„οΈ Detects CouchDB requests

Debug_Logic_Parameters

Information

⚠️ Detects debug parameters

ErrorPages-JobApps

Information

⚠️ Detects error page requests

Firebase DB detected

Information

πŸ”₯ Detects Firebase requests

Fortinet_Request

Information

πŸ›‘οΈ Detects Fortinet requests

GraphQL_Endpoint

Information

πŸ”— Detects GraphQL endpoints

IDOR_parameters

Information

πŸ”“ Detects IDOR-prone parameters

Jira_Request

Information

πŸ“‹ Detects Jira requests

Key_Parameters

Information

πŸ”‘ Detects key/token parameters

LFI_RFI_Parameters

Information

πŸ“‚ Detects LFI/RFI-prone parameters

MAGMI_Request

Information

πŸ–₯️ Detects MAGMI requests

Netsweeper_Request

Information

πŸ–₯️ Detects Netsweeper requests

OAuth_parameters

Information

πŸ”‘ Detects OAuth parameters

OpenRedirect_SSRF_Parameters

Information

πŸ”„ Detects redirect/URL parameters

RCE_Parameters

Information

⚑ Detects RCE-prone parameters

RegisterUser_parameters

Information

πŸ‘€ Detects registration parameters

SQLi_Parameters

Information

πŸ—„οΈ Detects SQLi-prone parameters

SSTI_Parameters

Information

πŸ”§ Detects SSTI-prone parameters

Secret-keywords-SecLists

Information

πŸ”‘ Detects secret keywords

Secrets_Request

Information

πŸ”‘ Detects secrets in requests

Solarwinds_Orion_Request

Information

πŸ–₯️ Detects SolarWinds requests

Springboot_Requests

Information

πŸƒ Detects Spring Boot requests

Swagger_Request

Information

πŸ“„ Detects Swagger requests

Token_Parameters

Information

πŸ”‘ Detects token parameters

URL_Path_as_a_Value

Information

πŸ”— Detects URL paths in parameters

URL_as_a_Value

Information

πŸ”— Detects URLs in parameters

UUID_Request

Information

πŸ”’ Detects UUIDs in requests

UserEnum_parameters

Information

πŸ‘€ Detects user enumeration parameters

WeblogicServer-UDDI_Explorer

Information

πŸ–₯️ Detects WebLogic UDDI

Weblogic_Request

Information

πŸ–₯️ Detects WebLogic requests

XSS_Parameters

Information

πŸ’‰ Detects XSS-prone parameters

Last updated