Labs & practice targets
Lab · multi-vuln

OWASP VulnerableApp

Deliberately-vulnerable app covering SQLi, XSS, SSRF, XXE, IDOR, JWT, upload, traversal, and auth, with deterministic ground truth and a scanner-comparison endpoint.

Use responsibly

Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.

More labs & practice targets