Lab · web-app
Snyk Goof
Snyk's vulnerable Node.js/Express/MongoDB demo app with exploitable npm packages and code-level flaws (open redirect, NoSQLi, XSS).
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Tagsweb-app
More labs & practice targets
- Altoro Mutual (AltoroJ)web-appClassic sample banking J2EE web app demonstrating real-world application security issues; also self-hostable.
- BodgeIt Storeweb-appSelf-contained Java/JSP vulnerable app aimed at pentest beginners, covering XSS, SQLi and hidden content.
- Butterfly Security Projectweb-appEducational PHP/MySQL environment teaching common web/PHP vulnerabilities alongside their mitigations.
- bWAPPweb-appFree open-source 'buggy web app' with 100+ vulnerabilities for practicing web security and preparing for pentests.
- CVWA (Conviso Vulnerable Web Application)web-appPurposely insecure PHP blog simulating a novice's code, used to teach manual and automated vulnerability detection and remediation.
- Cyclone Transfersweb-appRuby on Rails application from the Broken Web Applications (BWA) project for local security testing.