Lab · multi-vuln
Mutillidae II
App with 40+ classic web vulnerabilities, REST/SOAP, hints, and secure/insecure modes for breadth and scanner regression.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Tagsmulti-vuln
More labs & practice targets
- OWASP VulnerableAppmulti-vulnDeliberately-vulnerable app covering SQLi, XSS, SSRF, XXE, IDOR, JWT, upload, traversal, and auth, with deterministic ground truth and a scanner-comparison endpoint.
- AI-GoatllmVulnerable-LLM CTF challenges aligned to the OWASP Top 10 for LLM Applications, running a local Vicuna model (no cloud fees).
- Altoro Mutual (AltoroJ)web-appClassic sample banking J2EE web app demonstrating real-world application security issues; also self-hostable.
- AuthLab (digininja)authSelection of authentication and authorization challenges drawn from real-world examples, written in Go.
- BodgeIt Storeweb-appSelf-contained Java/JSP vulnerable app aimed at pentest beginners, covering XSS, SQLi and hidden content.
- Broken CrystalsspaModern React/Node application with REST and GraphQL for modern SPA testing.