Labs & practice targets
Lab · spa

Scriptease

Vulnerable client-side JavaScript SPA (no backend) demonstrating XSS, open redirect, prototype pollution, ReDoS and request hijacking.

Use responsibly

Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.

Tagsspa

More labs & practice targets