All resources
Topic

web-app

49 resources across 4 kinds

Tools

  1. XSRFProbeactivelicence

    A Python CSRF audit toolkit that crawls a target web app and runs 25+ checks for anti-CSRF token weaknesses, referer/origin validation bypasses and SameSite cookie issues, generating exploitable PoC payloads and JSON reports. GPLv3, v3.0.0, actively maintained.

    Open ↗
  2. AI Vuln Scanneractivecloud cost

    A security research CLI that automates web-application vulnerability scanning with OWASP ZAP (spider + active attack) and uses the Anthropic Claude API to analyze findings and generate Markdown remediation reports. Ships an intentionally vulnerable Flask app as a safe test target.

    Open ↗
  3. XSSeractivehigh-riskdual-uselicence

    XSSer (Cross Site Scripter) is an automated framework to detect, exploit and report XSS vulnerabilities in web apps, shipping 1,500+ attack vectors with a context-aware validation engine, WAF bypassers and encoding evasion, injection across GET/POST params, cookies and DOM, and PDF/XML/JSON reporting. Python 3 with CLI and GTK GUI.

    Open ↗
  4. The official add-on repository for OWASP ZAP (Zed Attack Proxy), the open-source dynamic application security testing (DAST) scanner. Contains the modular add-ons (in the addOns directory, built with Gradle) that extend ZAP's active/passive scanning, fuzzing, and web-app testing capabilities; tagged appsec, security, and dast.

    Open ↗

Frameworks & agents

  1. Claude-BugHunteractivedual-use

    A Claude Code skill bundle for authorized security testing, providing 83 skills, 15 slash commands and pattern databases with hunt templates for 58 web vulnerability classes (XSS, SQLi, SSRF, IDOR) plus recon/OSINT and reporting workflows. Includes authorization gates and excludes internal AD, C2 and post-exploitation.

    Open ↗
  2. Agent skills for Claude Code, Gemini CLI or other Skills/MCP agents that analyze mitmproxy-captured traffic for vulnerability classes such as IDOR, SSRF, SQLi, auth and secrets, distilled from disclosed HackerOne bug bounty reports.

    Open ↗

Labs & practice targets

  1. Classic sample banking J2EE web app demonstrating real-world application security issues; also self-hostable.

    Open ↗
  2. Self-contained Java/JSP vulnerable app aimed at pentest beginners, covering XSS, SQLi and hidden content.

    Open ↗
  3. Educational PHP/MySQL environment teaching common web/PHP vulnerabilities alongside their mitigations.

    Open ↗
  4. Free open-source 'buggy web app' with 100+ vulnerabilities for practicing web security and preparing for pentests.

    Open ↗
  5. Purposely insecure PHP blog simulating a novice's code, used to teach manual and automated vulnerability detection and remediation.

    Open ↗
  6. Ruby on Rails application from the Broken Web Applications (BWA) project for local security testing.

    Open ↗
  7. Single-file Python vulnerable web app (<100 lines) supporting most popular web vulnerability classes for education.

    Open ↗
  8. Damn Vulnerable Java EE application for security testing, runnable via Docker Compose, Maven Jetty or a Tomcat WAR.

    Open ↗
  9. Damn vulnerable Node.js app with varying difficulty levels for practicing common web vulnerabilities.

    Open ↗
  10. Node/Express/Sequelize app demonstrating the OWASP Top 10 with a developer security guidebook and a fixes branch.

    Open ↗
  11. Python app (inspired by DVWA) with session fixation, SQLi, stored XSS and weak-password vulnerabilities.

    Open ↗
  12. Short PHP web app whose vulnerabilities naive scanners fail to detect — useful for testing scanner depth.

    Open ↗
  13. PHP/Docker deliberately insecure web application for security practice.

    Open ↗
  14. Intentionally vulnerable Django employee-portal app (inspired by RailsGoat) containing OWASP Top 10 flaws.

    Open ↗
  15. Intentionally vulnerable Django app with master and broken branches for learning security testing with ZAP.

    Open ↗
  16. Broken Java web app illustrating bugs and vulnerabilities: memory leaks, deadlocks, JVM crash, injection (SQL/LDAP/code/OS), XSS, CSRF, XXE and traversal.

    Open ↗
  17. Node/Express/MongoDB app covering OWASP Top 10 injection, NoSQLi and OS command injection for app-security learning.

    Open ↗
  18. Small Python web app for text snippets/files with intentional XSS, XSRF, information-disclosure, DoS and RCE bugs (Google codelab).

    Open ↗
  19. Deliberately insecure Rails app with simulated users and sensitive card data for security testing and training.

    Open ↗
  20. Vulnerable Java/Docker demo application.

    Open ↗
  21. OWASP Mutillidae II — free PHP web-security training target with 40+ vulnerabilities and broad coverage.

    Open ↗
  22. OWASP Node.js/MongoDB app teaching how the OWASP Top 10 apply to Node apps, with a tutorial and vulnerable target.

    Open ↗
  23. Node.js/PostgreSQL app with real (not simulated) vulnerable code for benchmarking source-code analyzers and white-box testing.

    Open ↗
  24. Vulnerable e-commerce web app (Next.js/React/Node) for security practice.

    Open ↗
  25. PHP vulnerable web application for security practice.

    Open ↗
  26. PHP/MySQL learning platform where each 'brick' contains a security issue to exploit manually or with tools.

    Open ↗
  27. Deliberately vulnerable Ruby on Rails app with per-version tutorials demonstrating security issues and their fixes.

    Open ↗
  28. Web and mobile app security training platform with lessons and challenges based on the OWASP Top Ten.

    Open ↗
  29. Docker lab examples for the Security Knowledge Framework, correlated to KB IDs and controls (ASVS, NIST) with write-ups.

    Open ↗
  30. Learning platform for common web security flaws with .NET-specific lessons.

    Open ↗
  31. Image-gallery PHP/MySQL app with controlled vulnerabilities providing a safe, legal environment to practice common web attacks.

    Open ↗
  32. Vulnerable Play (Scala) app demonstrating unvalidated client input trusted and reflected into responses.

    Open ↗
  33. Globo.com collection of many intentionally vulnerable web apps across multiple stacks, each with attack narratives and Docker options.

    Open ↗
  34. Snyk's vulnerable Node.js/Express/MongoDB demo app with exploitable npm packages and code-level flaws (open redirect, NoSQLi, XSS).

    Open ↗
  35. Java/Spring Boot app demonstrating OWASP Top 10 and other security vulnerabilities.

    Open ↗
  36. Java/Tomcat/MySQL vulnerable app from the Cyber Security and Privacy Foundation for learning web vulnerabilities and secure coding.

    Open ↗
  37. Minimal Node/Express app demonstrating SQLi and XSS.

    Open ↗
  38. PHP/Docker web vulnerability lab project by Yavuzlar.

    Open ↗
  39. Deliberately insecure Java teaching app with lesson-based coverage of common JVM web vulnerabilities.

    Open ↗
  40. OWASP port of WebGoat to PHP/MySQL — interactive lessons where you exploit each vulnerability to demonstrate understanding.

    Open ↗
  41. Learning resource by Omar Santos bundling many intentionally vulnerable applications in Docker containers for training.

    Open ↗
  42. Deliberately vulnerable health-tech platform (React/Node/Postgres) with an AI chatbot for learning app security and ethical hacking.

    Open ↗

References

  1. A community-maintained collection of scripts and tips for OWASP ZAP (Zed Attack Proxy), organized by category including active scan, passive scan, authentication, encode/decode, HTTP fuzzing, payload generation, and WebSocket testing, written in Python, JavaScript, Kotlin, Ruby and others. Scripts are installable via the ZAP Marketplace and released under Apache 2.0.

    Open ↗