Labs & practice targets
Deliberately-vulnerable apps to practice on — in an environment you control.
- Open ↗
Classic sample banking J2EE web app demonstrating real-world application security issues; also self-hostable.
- Open ↗
Selection of authentication and authorization challenges drawn from real-world examples, written in Go.
- Open ↗BodgeIt Storeweb-app
Self-contained Java/JSP vulnerable app aimed at pentest beginners, covering XSS, SQLi and hidden content.
- Open ↗
Modern React/Node application with REST and GraphQL for modern SPA testing.
- Open ↗Butterfly Security Projectweb-app
Educational PHP/MySQL environment teaching common web/PHP vulnerabilities alongside their mitigations.
- Open ↗
Purposely insecure PHP blog simulating a novice's code, used to teach manual and automated vulnerability detection and remediation.
- Open ↗Cyclone Transfersweb-app
Ruby on Rails application from the Broken Web Applications (BWA) project for local security testing.
- Open ↗
Single-file Python vulnerable web app (<100 lines) supporting most popular web vulnerability classes for education.
- Open ↗Damn Vulnerable Application Scanner (DVAS)scanner-test
Intentionally vulnerable web application scanner target.
- Open ↗
Deliberately vulnerable C#/.NET API-only application for learning and practicing API security.
- Open ↗Damn Vulnerable File Upload (DVFU)file-upload
Collection of file-upload bypass techniques for learning and testing.
- Open ↗
Intentionally insecure AWS Lambda functions mapped to the OWASP Serverless Top 10 for learning FaaS security.
- Open ↗Damn Vulnerable Infrastructure (DVI)infrastructure
Fully simulated self-hosted vulnerable infrastructure with routers, subnetworks, SCADA and many vulnerable containers modeling an energy-management system.
- Open ↗
Damn Vulnerable Java EE application for security testing, runnable via Docker Compose, Maven Jetty or a Tomcat WAR.
- Open ↗
Sample LLM ReAct chatbot (Langchain) for learning prompt injection against Thought/Action/Observation agent loops.
- Open ↗
Damn vulnerable Node.js app with varying difficulty levels for practicing common web vulnerabilities.
- Open ↗
Node/Express/Sequelize app demonstrating the OWASP Top 10 with a developer security guidebook and a fixes branch.
- Open ↗
Python app (inspired by DVWA) with session fixation, SQLi, stored XSS and weak-password vulnerabilities.
- Open ↗
Stateful FastAPI game teaching privilege escalation and long-horizon API workflows with attack/fix modes.
- Open ↗
Deliberately vulnerable serverless (Node on AWS/Azure) application for learning serverless security.
- Open ↗
Short PHP web app whose vulnerabilities naive scanners fail to detect — useful for testing scanner depth.
- Open ↗Damn Vulnerable Web Socketswebsocket
Vulnerable web application using Web Sockets for client-server communication, with a DVWA-like flow.
- Open ↗
PHP/Docker deliberately insecure web application for security practice.
- Open ↗DjangoGoat (red-and-black)web-app
Intentionally vulnerable Django app with master and broken branches for learning security testing with ZAP.
- Open ↗
GraphQL-focused vulnerable app covering introspection, mutations, batching, JWT, SSRF, injections, and traversal.
- Open ↗DVWA (Damn Vulnerable Web Application)classic-injection
Classic PHP training app covering injection, CSRF, uploads, and command execution across multiple security levels.
- Open ↗
Node/Express/MongoDB app covering OWASP Top 10 injection, NoSQLi and OS command injection for app-security learning.
- Open ↗
Vulnerable Laravel API (student-grades theme) aligned to the OWASP API Security Top 10; bugs are visible, not hidden.
- Open ↗
Small Python web app for text snippets/files with intentional XSS, XSRF, information-disclosure, DoS and RCE bugs (Google codelab).
- Open ↗
Online platform of hands-on hacking machines and challenges for skill-building (VM/CTF style).
- Open ↗Insecure Deserialisation .NET PoCdeserialization
Small .NET webserver vulnerable to insecure deserialization.
- Open ↗
Series of vulnerable VM images with documentation teaching Linux/Apache/PHP/MySQL (LAMP) security.
- Open ↗Mutillidaeweb-app
OWASP Mutillidae II — free PHP web-security training target with 40+ vulnerabilities and broad coverage.
- Open ↗Mutillidae IImulti-vuln
App with 40+ classic web vulnerabilities, REST/SOAP, hints, and secure/insecure modes for breadth and scanner regression.
- Open ↗
Node.js/PostgreSQL app with real (not simulated) vulnerable code for benchmarking source-code analyzers and white-box testing.
- Open ↗
MongoDB-backed PHP lab with two NoSQL injection scenarios for practicing the technique.
- Open ↗
Java/MongoDB app intentionally vulnerable to NoSQL injection, with secure and insecure code examples and docs.
- Open ↗OopsSec Storeweb-app
Vulnerable e-commerce web app (Next.js/React/Node) for security practice.
- Open ↗
PHP vulnerable web application for security practice.
- Open ↗OWASP Bricksweb-app
PHP/MySQL learning platform where each 'brick' contains a security issue to exploit manually or with tools.
- Open ↗OWASP crAPIapi
Realistic microservices app for advanced API testing: multi-user authorization, API chaining, and business workflows.
- Open ↗
PHP/Ratchet deliberately vulnerable WebSocket app for testing WebSocket security skills with ZAP or Burp.
- Open ↗
Modern Angular/Node SPA with REST APIs, access-control, business-logic, Web3, and AI/LLM vulnerabilities for browser navigation and long attack chains.
- Open ↗OWASP Juice Shopdeliberately-vulnerable-web-app
Modern deliberately-insecure web application (91+ scored challenges spanning injection, XSS, broken auth, IDOR/BOLA, crypto, business logic) used for security training and tool benchmarking.
- Open ↗OWASP RailsGoatweb-app
Deliberately vulnerable Ruby on Rails app with per-version tutorials demonstrating security issues and their fixes.
- Open ↗
Multi-user CTF/tournament platform with levels, scoring, and native grading for user isolation and competition.
- Open ↗OWASP Security Shepherdweb-app
Web and mobile app security training platform with lessons and challenges based on the OWASP Top Ten.
- Open ↗OWASP SKF Labsweb-app
Docker lab examples for the Security Knowledge Framework, correlated to KB IDs and controls (ASVS, NIST) with write-ups.
- Open ↗OWASP VulnerableAppmulti-vuln
Deliberately-vulnerable app covering SQLi, XSS, SSRF, XXE, IDOR, JWT, upload, traversal, and auth, with deterministic ground truth and a scanner-comparison endpoint.
- Open ↗OWASP VulnerableApp-facadescanner-test
Gateway that routes to a distributed farm of vulnerable apps (tech-stack agnostic), integrating VulnerableApp, -jsp and -php.
- Open ↗
Learning platform for common web security flaws with .NET-specific lessons.
- Open ↗OWASP WrongSecretssecrets-cloud
Training app for finding secrets in code, Git, containers, Kubernetes, and cloud environments.
- Open ↗Play-WebGoatweb-app
Vulnerable Play (Scala) app demonstrating unvalidated client input trusted and reflected into responses.
- Open ↗
Free online training with hundreds of per-technique labs across 31 web-vulnerability topics at Apprentice/Practitioner/Expert tiers, each with a defined success condition.
- Open ↗Puzzlemallsession
Java/JSP app for practicing session-puzzling attacks via different session sequences.
- Open ↗Scripteasespa
Vulnerable client-side JavaScript SPA (no backend) demonstrating XSS, open redirect, prototype pollution, ReDoS and request hijacking.
- Open ↗SecDevLabsweb-app
Globo.com collection of many intentionally vulnerable web apps across multiple stacks, each with attack narratives and Docker options.
- Open ↗Secure Code Gamecode-review
GitHub Security Lab in-repo learning experience where you secure intentionally vulnerable code.
- Open ↗
Collection of pages vulnerable to SQL injection across multiple DBMSs, with a deployment script for a full test machine.
- Open ↗SSRF Vuln Labssrf
PHP lab with six SSRF scenarios including IP blacklist bypass, DNS rebinding, and HTML-to-PDF SSRF.
- Open ↗
Focused playground for practicing template injection across many template engines.
- Open ↗TicketMagpieweb-app
Java/Spring Boot app demonstrating OWASP Top 10 and other security vulnerabilities.
- Open ↗Tiredful APIapi
Intentionally broken Django REST API teaching information disclosure, IDOR, access control, throttling and injection flaws.
- Open ↗
Very vulnerable Node/Express web app and API (Swagger/Sqlite/Sequelize) for testing security tools and pentesting.
- Open ↗
Java/Tomcat/MySQL vulnerable app from the Cyber Security and Privacy Foundation for learning web vulnerabilities and secure coding.
- Open ↗
Minimal Node/Express app demonstrating SQLi and XSS.
- Open ↗
PHP app with Google Authenticator TOTP for practicing OTP and two-factor authentication bypass.
- Open ↗Vulnerable SAML Appsaml-sso
IdP and SP Docker images showcasing exploitable SAML configurations such as privilege escalation via modified SAML responses.
- Open ↗
Example Python (Bottle) API vulnerable to TLS issues, user enumeration, auth bypass, SQLi and session-management flaws.
- Open ↗
Vulnerable .NET/C# API built for educational purposes.
- Open ↗
.NET console app illustrating XSLT-transform vulnerabilities relevant to web apps processing XML.
- Open ↗VulnLab (Yavuzlar)web-app
PHP/Docker web vulnerability lab project by Yavuzlar.
- Open ↗WackoPickoscanner-test
Vulnerable app from the paper 'Why Johnny Can't Pentest', with known XSS, SQLi, traversal, file inclusion and command injection for scanner evaluation.
- Open ↗WebGoat and WebWolfguided-java
Guided OWASP Java lessons with callbacks and server/client vulnerabilities for early curriculum and tool-use instruction.
- Open ↗WebGoatPHPweb-app
OWASP port of WebGoat to PHP/MySQL — interactive lessons where you exploit each vulnerability to demonstrate understanding.
- Open ↗Websploit (santosomar)web-app
Learning resource by Omar Santos bundling many intentionally vulnerable applications in Docker containers for training.
- Open ↗Weird Proxies - Labsproxy
Test labs for reverse-proxy and related attacks (Nginx, Apache, HAProxy, Varnish, Traefik, Envoy, Caddy, AWS, Cloudflare), companion to the Weird Proxies cheat sheet.
- Open ↗
Simple PHP app containing an XML External Entity (XXE) vulnerability for learning and testing.
- Open ↗yrprey training familytraining-family
A family of deliberately-vulnerable practice apps (Node/Python/PHP APIs and web apps) for hands-on web-security training.
- Open ↗Zero Healthweb-app
Deliberately vulnerable health-tech platform (React/Node/Postgres) with an AI chatbot for learning app security and ethical hacking.
- Open ↗
A deliberately vulnerable bug-adoption e-commerce app (React, FastAPI, MariaDB) with 32 planted vulnerabilities across the OWASP Top 10, three difficulty levels and a scoring dashboard, deployed via Docker as a practice target. Includes RCE; must never be exposed to the internet.