All resources

Labs & practice targets

Deliberately-vulnerable apps to practice on — in an environment you control.

115 shown
  1. Vulnerable-LLM CTF challenges aligned to the OWASP Top 10 for LLM Applications, running a local Vicuna model (no cloud fees).

    Open ↗
  2. Classic sample banking J2EE web app demonstrating real-world application security issues; also self-hostable.

    Open ↗
  3. Selection of authentication and authorization challenges drawn from real-world examples, written in Go.

    Open ↗
  4. Self-contained Java/JSP vulnerable app aimed at pentest beginners, covering XSS, SQLi and hidden content.

    Open ↗
  5. Modern React/Node application with REST and GraphQL for modern SPA testing.

    Open ↗
  6. BugGPTgenerator

    Intentionally vulnerable application generator (Python/Flask/OpenAI) for creating security-training targets.

    Open ↗
  7. Educational PHP/MySQL environment teaching common web/PHP vulnerabilities alongside their mitigations.

    Open ↗
  8. bWAPPweb-app

    Free open-source 'buggy web app' with 100+ vulnerabilities for practicing web security and preparing for pentests.

    Open ↗
  9. CloudGoatcloudcloud costhosted

    Rhino Security Labs' 'vulnerable by design' AWS/Azure deployment tool with CTF-style cloud attack scenarios.

    Open ↗
  10. Completely Ridiculous API — intentionally vulnerable microservice API (vehicle-owner theme) built around the OWASP API Security Top 10 (BOLA/BFLA/mass assignment).

    Open ↗
  11. CryptOMGcrypto

    Configurable CTF-style testbed highlighting flaws in cryptographic implementations: oracles, side channels and ECB weaknesses.

    Open ↗
  12. Purposely insecure PHP blog simulating a novice's code, used to teach manual and automated vulnerability detection and remediation.

    Open ↗
  13. Ruby on Rails application from the Broken Web Applications (BWA) project for local security testing.

    Open ↗
  14. Single-file Python vulnerable web app (<100 lines) supporting most popular web vulnerability classes for education.

    Open ↗
  15. Intentionally vulnerable web application scanner target.

    Open ↗
  16. Deliberately vulnerable C#/.NET API-only application for learning and practicing API security.

    Open ↗
  17. Collection of file-upload bypass techniques for learning and testing.

    Open ↗
  18. Intentionally insecure AWS Lambda functions mapped to the OWASP Serverless Top 10 for learning FaaS security.

    Open ↗
  19. Fully simulated self-hosted vulnerable infrastructure with routers, subnetworks, SCADA and many vulnerable containers modeling an energy-management system.

    Open ↗
  20. Damn Vulnerable Java EE application for security testing, runnable via Docker Compose, Maven Jetty or a Tomcat WAR.

    Open ↗
  21. Sample LLM ReAct chatbot (Langchain) for learning prompt injection against Thought/Action/Observation agent loops.

    Open ↗
  22. Damn vulnerable Node.js app with varying difficulty levels for practicing common web vulnerabilities.

    Open ↗
  23. Node/Express/Sequelize app demonstrating the OWASP Top 10 with a developer security guidebook and a fixes branch.

    Open ↗
  24. Python app (inspired by DVWA) with session fixation, SQLi, stored XSS and weak-password vulnerabilities.

    Open ↗
  25. Stateful FastAPI game teaching privilege escalation and long-horizon API workflows with attack/fix modes.

    Open ↗
  26. Deliberately vulnerable serverless (Node on AWS/Azure) application for learning serverless security.

    Open ↗
  27. Short PHP web app whose vulnerabilities naive scanners fail to detect — useful for testing scanner depth.

    Open ↗
  28. Vulnerable web application using Web Sockets for client-server communication, with a DVWA-like flow.

    Open ↗
  29. PHP/Docker deliberately insecure web application for security practice.

    Open ↗
  30. DjanGoatweb-app

    Intentionally vulnerable Django employee-portal app (inspired by RailsGoat) containing OWASP Top 10 flaws.

    Open ↗
  31. Intentionally vulnerable Django app with master and broken branches for learning security testing with ZAP.

    Open ↗
  32. GraphQL-focused vulnerable app covering introspection, mutations, batching, JWT, SSRF, injections, and traversal.

    Open ↗
  33. Classic PHP training app covering injection, CSRF, uploads, and command execution across multiple security levels.

    Open ↗
  34. Damn Vulnerable Web Services (Node) — app with a web service and API covering IDOR, mass assignment, NoSQL/SQLi, SSRF, JWT and XXE.

    Open ↗
  35. EasyBuggyweb-app

    Broken Java web app illustrating bugs and vulnerabilities: memory leaks, deadlocks, JVM crash, injection (SQL/LDAP/code/OS), XSS, CSRF, XXE and traversal.

    Open ↗
  36. Node/Express/MongoDB app covering OWASP Top 10 injection, NoSQLi and OS command injection for app-security learning.

    Open ↗
  37. FFUF.mefuzzinghosted

    Target practice environment for the ffuf web fuzzer.

    Open ↗
  38. Vulnerable Laravel API (student-grades theme) aligned to the OWASP API Security Top 10; bugs are visible, not hidden.

    Open ↗
  39. Google Gruyereweb-apphosted

    Small Python web app for text snippets/files with intentional XSS, XSRF, information-disclosure, DoS and RCE bugs (Google codelab).

    Open ↗
  40. Vulnerable-by-design Go/gRPC lab for learning and practicing gRPC security.

    Open ↗
  41. HackTheBoxplatformhosted

    Online platform of hands-on hacking machines and challenges for skill-building (VM/CTF style).

    Open ↗
  42. Hammerweb-app

    Deliberately insecure Rails app with simulated users and sensitive card data for security testing and training.

    Open ↗
  43. Small .NET webserver vulnerable to insecure deserialization.

    Open ↗
  44. Small PHP app for practicing attacks against JWT tokens.

    Open ↗
  45. Series of vulnerable VM images with documentation teaching Linux/Apache/PHP/MySQL (LAMP) security.

    Open ↗
  46. Marathonweb-app

    Vulnerable Java/Docker demo application.

    Open ↗
  47. Mutillidaeweb-app

    OWASP Mutillidae II — free PHP web-security training target with 40+ vulnerabilities and broad coverage.

    Open ↗
  48. Mutillidae IImulti-vuln

    App with 40+ classic web vulnerabilities, REST/SOAP, hints, and secure/insecure modes for breadth and scanner regression.

    Open ↗
  49. NodeGoatwhite-box-javascript

    OWASP deliberately-vulnerable Node.js app for white-box source analysis and patching.

    Open ↗
  50. NodeGoatweb-app

    OWASP Node.js/MongoDB app teaching how the OWASP Top 10 apply to Node apps, with a tutorial and vulnerable target.

    Open ↗
  51. Node.js/PostgreSQL app with real (not simulated) vulnerable code for benchmarking source-code analyzers and white-box testing.

    Open ↗
  52. MongoDB-backed PHP lab with two NoSQL injection scenarios for practicing the technique.

    Open ↗
  53. Java/MongoDB app intentionally vulnerable to NoSQL injection, with secure and insecure code examples and docs.

    Open ↗
  54. Vulnerable e-commerce web app (Next.js/React/Node) for security practice.

    Open ↗
  55. PHP vulnerable web application for security practice.

    Open ↗
  56. PHP/MySQL learning platform where each 'brick' contains a security issue to exploit manually or with tools.

    Open ↗
  57. Realistic microservices app for advanced API testing: multi-user authorization, API chaining, and business workflows.

    Open ↗
  58. PHP/Ratchet deliberately vulnerable WebSocket app for testing WebSocket security skills with ZAP or Burp.

    Open ↗
  59. Modern Angular/Node SPA with REST APIs, access-control, business-logic, Web3, and AI/LLM vulnerabilities for browser navigation and long attack chains.

    Open ↗
  60. OWASP Juice Shopdeliberately-vulnerable-web-app

    Modern deliberately-insecure web application (91+ scored challenges spanning injection, XSS, broken auth, IDOR/BOLA, crypto, business logic) used for security training and tool benchmarking.

    Open ↗
  61. Deliberately vulnerable Ruby on Rails app with per-version tutorials demonstrating security issues and their fixes.

    Open ↗
  62. Multi-user CTF/tournament platform with levels, scoring, and native grading for user isolation and competition.

    Open ↗
  63. Web and mobile app security training platform with lessons and challenges based on the OWASP Top Ten.

    Open ↗
  64. Docker lab examples for the Security Knowledge Framework, correlated to KB IDs and controls (ASVS, NIST) with write-ups.

    Open ↗
  65. Deliberately-vulnerable app covering SQLi, XSS, SSRF, XXE, IDOR, JWT, upload, traversal, and auth, with deterministic ground truth and a scanner-comparison endpoint.

    Open ↗
  66. Gateway that routes to a distributed farm of vulnerable apps (tech-stack agnostic), integrating VulnerableApp, -jsp and -php.

    Open ↗
  67. Learning platform for common web security flaws with .NET-specific lessons.

    Open ↗
  68. OWASP WrongSecretssecrets-cloud

    Training app for finding secrets in code, Git, containers, Kubernetes, and cloud environments.

    Open ↗
  69. PAYGoatbusiness-logic

    Payment-focused vulnerable app covering payment manipulation, BOLA, races, balances, and business-logic failures — especially relevant to real bug bounties.

    Open ↗
  70. Peruggiaweb-app

    Image-gallery PHP/MySQL app with controlled vulnerabilities providing a safe, legal environment to practice common web attacks.

    Open ↗
  71. Pixiapi

    OWASP DevSlop MEAN-stack app with deliberately insecure APIs for scanning and API-security demos.

    Open ↗
  72. Vulnerable Play (Scala) app demonstrating unvalidated client input trusted and reflected into responses.

    Open ↗
  73. PortSwigger Web Security Academyonline-labs-platformhosted

    Free online training with hundreds of per-technique labs across 31 web-vulnerability topics at Apprentice/Practitioner/Expert tiers, each with a defined success condition.

    Open ↗
  74. Puzzlemallsession

    Java/JSP app for practicing session-puzzling attacks via different session sequences.

    Open ↗
  75. PyGoatwhite-box-python

    Deliberately-vulnerable Python/Django app for white-box source analysis and patching.

    Open ↗
  76. RailsGoatwhite-box-ruby

    OWASP deliberately-vulnerable Ruby on Rails app for white-box source analysis and patching.

    Open ↗
  77. Vulnerable client-side JavaScript SPA (no backend) demonstrating XSS, open redirect, prototype pollution, ReDoS and request hijacking.

    Open ↗
  78. SecDevLabsweb-app

    Globo.com collection of many intentionally vulnerable web apps across multiple stacks, each with attack narratives and Docker options.

    Open ↗
  79. Secure Code Gamecode-review

    GitHub Security Lab in-repo learning experience where you secure intentionally vulnerable code.

    Open ↗
  80. Snyk Goofweb-app

    Snyk's vulnerable Node.js/Express/MongoDB demo app with exploitable npm packages and code-level flaws (open redirect, NoSQLi, XSS).

    Open ↗
  81. Collection of pages vulnerable to SQL injection across multiple DBMSs, with a deployment script for a full test machine.

    Open ↗
  82. Progressive PHP labs to learn SQL injection: error-based, blind (boolean/time), update/insert, header and second-order injection, and WAF bypass.

    Open ↗
  83. SQLolsqli

    SQL injection test application, now part of the Magical Code Injection Rainbow (MCIR) framework.

    Open ↗
  84. PHP lab with six SSRF scenarios including IP blacklist bypass, DNS rebinding, and HTML-to-PDF SSRF.

    Open ↗
  85. Focused playground for practicing template injection across many template engines.

    Open ↗
  86. Java/Spring Boot app demonstrating OWASP Top 10 and other security vulnerabilities.

    Open ↗
  87. Intentionally broken Django REST API teaching information disclosure, IDOR, access control, throttling and injection flaws.

    Open ↗
  88. TryHackMeplatformhosted

    Guided online rooms and labs teaching offensive and defensive security through hands-on exercises.

    Open ↗
  89. Vulnerable REST API teaching BOLA, mass assignment, JWT, SQLi, enumeration, and rate limits, with vulnerable and secure modes as positive/negative controls.

    Open ↗
  90. vAPIapi

    Vulnerable Adversely Programmed Interface — self-hostable PHP/Laravel API mirroring the OWASP API Top 10 through exercises.

    Open ↗
  91. Vulhubreal-cvetraining only

    Containerized historical CVEs in real products for real-CVE training.

    Open ↗
  92. Very vulnerable Node/Express web app and API (Swagger/Sqlite/Sequelize) for testing security tools and pentesting.

    Open ↗
  93. Java/Tomcat/MySQL vulnerable app from the Cyber Security and Privacy Foundation for learning web vulnerabilities and secure coding.

    Open ↗
  94. Minimal Node/Express app demonstrating SQLi and XSS.

    Open ↗
  95. PHP app with Google Authenticator TOTP for practicing OTP and two-factor authentication bypass.

    Open ↗
  96. IdP and SP Docker images showcasing exploitable SAML configurations such as privilege escalation via modified SAML responses.

    Open ↗
  97. Example Python (Bottle) API vulnerable to TLS issues, user enumeration, auth bypass, SQLi and session-management flaws.

    Open ↗
  98. Vulnerable .NET/C# API built for educational purposes.

    Open ↗
  99. .NET console app illustrating XSLT-transform vulnerabilities relevant to web apps processing XML.

    Open ↗
  100. VulnHubplatformhosted

    Repository of downloadable deliberately vulnerable VM images to practice exploitation in your own lab.

    Open ↗
  101. PHP/Docker web vulnerability lab project by Yavuzlar.

    Open ↗
  102. WackoPickoscanner-test

    Vulnerable app from the paper 'Why Johnny Can't Pentest', with known XSS, SQLi, traversal, file inclusion and command injection for scanner evaluation.

    Open ↗
  103. WAVSEPscanner-regression

    Web application vulnerability scanner evaluation project providing deterministic scanner test cases for high-volume regression.

    Open ↗
  104. WAVSEPscanner-test

    Web Application Vulnerability Scanner Evaluation Project — vulnerable app for assessing scanner accuracy and coverage.

    Open ↗
  105. WebGoatweb-app

    Deliberately insecure Java teaching app with lesson-based coverage of common JVM web vulnerabilities.

    Open ↗
  106. Guided OWASP Java lessons with callbacks and server/client vulnerabilities for early curriculum and tool-use instruction.

    Open ↗
  107. WebGoatPHPweb-app

    OWASP port of WebGoat to PHP/MySQL — interactive lessons where you exploit each vulnerability to demonstrate understanding.

    Open ↗
  108. App based on willingly vulnerable RESTful APIs (Angular/Node).

    Open ↗
  109. Learning resource by Omar Santos bundling many intentionally vulnerable applications in Docker containers for training.

    Open ↗
  110. Test labs for reverse-proxy and related attacks (Nginx, Apache, HAProxy, Varnish, Traefik, Envoy, Caddy, AWS, Cloudflare), companion to the Weird Proxies cheat sheet.

    Open ↗
  111. Focused playground for practicing XSS across many injection contexts.

    Open ↗
  112. Simple PHP app containing an XML External Entity (XXE) vulnerability for learning and testing.

    Open ↗
  113. yrprey training familytraining-family

    A family of deliberately-vulnerable practice apps (Node/Python/PHP APIs and web apps) for hands-on web-security training.

    Open ↗
  114. Deliberately vulnerable health-tech platform (React/Node/Postgres) with an AI chatbot for learning app security and ethical hacking.

    Open ↗
  115. BugStoredeliberately-vulnerable-web-apptraining only

    A deliberately vulnerable bug-adoption e-commerce app (React, FastAPI, MariaDB) with 32 planted vulnerabilities across the OWASP Top 10, three difficulty levels and a scoring dashboard, deployed via Docker as a practice target. Includes RCE; must never be exposed to the internet.

    Open ↗