Lab · deliberately-vulnerable-web-apptraining only
BugStore
A deliberately vulnerable bug-adoption e-commerce app (React, FastAPI, MariaDB) with 32 planted vulnerabilities across the OWASP Top 10, three difficulty levels and a scoring dashboard, deployed via Docker as a practice target. Includes RCE; must never be exposed to the internet.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Public solutions exist for this target — good for training, unsuitable as a final evaluation.
More labs & practice targets
- OWASP Juice Shopdeliberately-vulnerable-web-appModern deliberately-insecure web application (91+ scored challenges spanning injection, XSS, broken auth, IDOR/BOLA, crypto, business logic) used for security training and tool benchmarking.
- AI-GoatllmVulnerable-LLM CTF challenges aligned to the OWASP Top 10 for LLM Applications, running a local Vicuna model (no cloud fees).
- Altoro Mutual (AltoroJ)web-appClassic sample banking J2EE web app demonstrating real-world application security issues; also self-hostable.
- AuthLab (digininja)authSelection of authentication and authorization challenges drawn from real-world examples, written in Go.
- BodgeIt Storeweb-appSelf-contained Java/JSP vulnerable app aimed at pentest beginners, covering XSS, SQLi and hidden content.
- Broken CrystalsspaModern React/Node application with REST and GraphQL for modern SPA testing.