Highlights
🔥 New wordlists
- 🔥 feat(wordlist): Created 2025 most used passwords wordlist (PR #1263)
- 🔥 feat(wordlist): Added AI ethical and safety boundary testing wordlists (Commit d7400c8)
- 🔥 feat(wordlist): Updated top1million subdomains lists with cloudflare data (PR #1275)
- feat(wordlist): Add wordlists for: Kubernetes, Docker, Elasticsearch, Grafana, GitLab, Prometheus (PR #1293)
- feat(wordlist): Added OpenWRT discovery wordlist
- feat(wordlist): Added RSTP camera wordlist
- feat(wordlist): Added SOfensive LFI wordlist and removed redundant GracefulSecurity wordlist
- feat(wordlist): Added wordlist for Bluedit CMS
- feat(wordlist): Added locale-codes wordlist and language-codes wordlist
- feat(wordlist): Add
common.txtin brazilian portuguese (PR #1279) - feat(wordlist): Add more hispanic names (PR #1290)
- feat(wordlist): Added list of Brazilian names
- feat(wordlist): Added polish password wordlist (PR #1272)
- feat(wordlist): Added Polish wordlist to Passwords/Common-Credentials/Language-Specific
🌐 Updates to existing wordlists
- feat(wordlist): Added more API fuzzing endpoints
- feat(wordlist): Added more entries to "SAP-NetWeaver.txt" (PR #1255)
- feat(wordlist): Added more payloads to graphql wordlist (PR #1294)
- feat(wordlist): Added more payloads to login_bypass.txt
- feat(wordlist): Added more payloads to Swagger.txt
- feat(wordlist): Updated list of Spring endpoints. (PR #1253)
- feat(wordlist): Updated list of years in 'quickhits.txt' (PR #1287)
⚙️ Miscellanous cleanup
This release also includes wordlist cleanup and documentation fixes:
- chore(wordlist): Added 'regional_' prefix to country codes wordlists
- chore(wordlist): Classify LFI wordlists by OS
- chore(wordlist): Moved 'rstp.txt' wordlist from fuzzing to Discovery/Web-Content/Service-Specific
- chore(wordlist): Re-added JWT secrets from PR #1235
- chore(wordlist): Removed duplicates from login_bypass.txt
- chore(wordlist): Removed useless wordlist 'der-postillon.txt'
- chore(wordlist): Renamed Windows LFI wordlist from adeadfed
New Contributors
- @willcipher made their first contribution in #1255
- @TeaLeavesJumping made their first contribution in #1272
- @JooReb made their first contribution in #1278
- @SQU4NCH made their first contribution in #1279
- @marcel2012 made their first contribution in #1287
- @valerodev made their first contribution in #1290
- @0xBassia made their first contribution in #1293
- @Mugeha made their first contribution in #1294
Full Changelog: 2025.3...2026.1