There are 11 repositories under vulnerable-web-app topic.
Vulnerable app with examples showing how to not use secrets
:warning: This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory
OWASP Vulnerable Web Application Project https://github.com/hummingbirdscyber
A built-to-be-vulnerable API application based on the OWASP top 10 API vulnerabilities. Use c{api}tal to learn, train and exploit API Security vulnerabilities within your own API Security CTF.
Vulnerable Banking Suite
Workshop on Template Injection (6 exercises) covering Twig, Jinja2, Tornado, Velocity and Freemaker engines.
A simple PHP application to learn SQL Injection detection and exploitation techniques.
This is a dockerized application that is vulnerable to the Spring4Shell vulnerability (CVE-2022-22965).
The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.
Vulnerable API for research and education
Zero trust. Zero security. Total exposure. A deliberately vulnerable health tech platform with AI Chatbot for learning about application security and ethical hacking. It contains vulnerabilities from OWASP top 10 Web, API and AI/LLM Security Vulnerabilities. Highly vulnerable, never use in production.
A server vulnerable to XXE that can be used to test payloads using the xxer tool.
WebSafeHub - Vulnerable Web App
📧 [Research] E-Mail Injection: Vulnerable applications
This project is a vulnerable web application to practice on. It is designed for educational purposes to help security enthusiasts and developers understand and mitigate common web vulnerabilities.
Vulnerable Web application made with PHP/SQL designed to help new web testers gain some experience and test DAST tools for identifying web vulnerabilities. Containing some of the most well-known vulnerabilities such as SQL, cross-site scripting (XSS), OS command injections, our intention to expand more vulnerabilities for learning purposes.
OWASP Foundation Web Respository
Vulnerable FastAPI in reference to Opensource Web Application Security Project (OWASP) TOP 10: 2021
This is a collection of vulnerable machines that can help you to learn hacking, pentesting and bug hunting. I know there are a lot of lists out there, but most of them are not updated regularly. So I decided to make on myself. Hope this will help you
A website developed with Nodejs. This website includes server side prototype pollution vulnerability
ThreatByte is a vulnerable Python (Flask) web application designed to demonstrate some Web Application and API Security risks.
LEKIR - Vulnerable by design to help people learn about common web security, dockerized!
Intentionally vulnerable Python / Flask application, built for educational purposes.
⛔️deprecated and replaced by https://github.com/marmicode/websheep
Provide a collection of deliberately vulnerable APIs along with corresponding challenges to help enhancing their skills in identifying, exploiting, and securing API vulnerabilities.
"InsecureTrust_Bank: Educational repo demonstrating web app vulnerabilities like SQL injection & XSS for security awareness. Use responsibly.
Erlik 2 - Vulnerable-Flask-App
A TUI enviorment for vulnerable app containers.
Small forum website for practicing basic web exploits.
IOTgoat is a vulnerable firmware made by the OWASP project. This is a custom made version of the 'IOTgoat firmware' built for the A5-V11 mini 3G router. This branch brings back the vulnerable IOT firmware back to a real IOT device, for a more realistic experience of IOT device exploitation on a budget.
Intentionally Vulnerable Pages for OWASP ASVS Security Evaluation Templates with Nuclei Project. https://snbig.github.io/Vulnerable-Pages/
Z-Vulnerable-Website-Project (ZVP for short) is a project where I try to create a custom vulnerable website for learning and demonstrating common web security flaws.