Labs & practice targets
Lab · deliberately-vulnerable-web-apptraining only

BugStore

A deliberately vulnerable bug-adoption e-commerce app (React, FastAPI, MariaDB) with 32 planted vulnerabilities across the OWASP Top 10, three difficulty levels and a scoring dashboard, deployed via Docker as a practice target. Includes RCE; must never be exposed to the internet.

Use responsibly

Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.

Public solutions exist for this target — good for training, unsuitable as a final evaluation.

More labs & practice targets