There are 4 repositories under vulnerable-web-application topic.
:warning: This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory
The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.
VulnerableApp-facade is probably most modern lightweight distributed farm of Vulnerable Applications built for handling wide range of vulnerabilities across tech stacks.
Vulnerable API for research and education
WebSafeHub - Vulnerable Web App
đź“§ [Research] E-Mail Injection: Vulnerable applications
OWASP Foundation Web Respository
vuln-netframework is a .net-framework 4.7 project that include worst coding practices about common vulnerabilities like Insecure Deserialization, Os Command Injection, SQL Injection, etc.
Some vulnerables docker webapps
Unofficial VirtualBox virtual machine instance of OWASP Juice Shop
"InsecureTrust_Bank: Educational repo demonstrating web app vulnerabilities like SQL injection & XSS for security awareness. Use responsibly.
Vulnerabilities scanner tool
A simple vulnerable token machine written in python.
A Spring-Boot based web application for booking flights (fake data) that may contains vulnerabilities. Course project for UCD COMP47660 Secure Software Engineering
Infosec Coffee is a deliberately vulnerable web application to better understand interesting security flaws.
A really cool community web application... that's vulnerable (Made for CNY Hackathon 2019)
Bash script to install docker and OWASPs juice-shop vulnerable webapp. Run this and browse to http://localhost:3000
Hackademy is a Vulnerable Web Application, Made to practice and study the web security in depth from the Back-end perspective and understands how vulnerabilities get to arise
Vulnerable web app made for CNY Hackathon
VulnWeb - Learn & Fix Common Security Flaws
"SecureTrust_Bank: Educational repo demonstrating fixes for web app vulnerabilities like SQL injection & XSS for security awareness. Use responsibly.
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
Project for cybersecurity course 2019
a vulnerable web app made with PHP, used to demonstrate SQLIA
This is a very simple PHP website that can be used to demonstrate common vulnerabiltiies in web applications.