Wapiti allows you to audit the security of your web applications. It performs "black-box" scans; i.e., it does not study the source code of the application but will scans the webpages of the deployed webapp, looking for scripts and forms where it can inject data. Once it gets this list, Wapiti acts like a fuzzer, injecting payloads to see if a script is vulnerable.
For downloads and more information,
visit the Wapiti homepage.
Has come a long way since the version 2 branch. Now at Version 3.03 it has become an excellent tool in the arsenal. The ability to easily setup and run against many targets and get the results in json have provided a way to automatically manage all of our apps.