deliberately-vulnerable-web-app
2 resources across 1 kinds
Labs & practice targets
- Open ↗
Modern deliberately-insecure web application (91+ scored challenges spanning injection, XSS, broken auth, IDOR/BOLA, crypto, business logic) used for security training and tool benchmarking.
- Open ↗BugStoretraining only
A deliberately vulnerable bug-adoption e-commerce app (React, FastAPI, MariaDB) with 32 planted vulnerabilities across the OWASP Top 10, three difficulty levels and a scoring dashboard, deployed via Docker as a practice target. Includes RCE; must never be exposed to the internet.