Lab · web-apphosted
Google Gruyere
Small Python web app for text snippets/files with intentional XSS, XSRF, information-disclosure, DoS and RCE bugs (Google codelab).
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
A shared, hosted instance — for practice only, within the platform's own rules.
Tagsweb-app
More labs & practice targets
- Altoro Mutual (AltoroJ)web-appClassic sample banking J2EE web app demonstrating real-world application security issues; also self-hostable.
- BodgeIt Storeweb-appSelf-contained Java/JSP vulnerable app aimed at pentest beginners, covering XSS, SQLi and hidden content.
- Butterfly Security Projectweb-appEducational PHP/MySQL environment teaching common web/PHP vulnerabilities alongside their mitigations.
- bWAPPweb-appFree open-source 'buggy web app' with 100+ vulnerabilities for practicing web security and preparing for pentests.
- CVWA (Conviso Vulnerable Web Application)web-appPurposely insecure PHP blog simulating a novice's code, used to teach manual and automated vulnerability detection and remediation.
- Cyclone Transfersweb-appRuby on Rails application from the Broken Web Applications (BWA) project for local security testing.