web-app
49 resources across 4 kinds
Tools
- Open ↗AI Vuln Scanneractivecloud cost
A security research CLI that automates web-application vulnerability scanning with OWASP ZAP (spider + active attack) and uses the Anthropic Claude API to analyze findings and generate Markdown remediation reports. Ships an intentionally vulnerable Flask app as a safe test target.
- Open ↗XSSeractivehigh-riskdual-uselicence
XSSer (Cross Site Scripter) is an automated framework to detect, exploit and report XSS vulnerabilities in web apps, shipping 1,500+ attack vectors with a context-aware validation engine, WAF bypassers and encoding evasion, injection across GET/POST params, cookies and DOM, and PDF/XML/JSON reporting. Python 3 with CLI and GTK GUI.
- Open ↗ZAP Extensionsactive
The official add-on repository for OWASP ZAP (Zed Attack Proxy), the open-source dynamic application security testing (DAST) scanner. Contains the modular add-ons (in the addOns directory, built with Gradle) that extend ZAP's active/passive scanning, fuzzing, and web-app testing capabilities; tagged appsec, security, and dast.
Frameworks & agents
- Open ↗Claude-BugHunteractivedual-use
A Claude Code skill bundle for authorized security testing, providing 83 skills, 15 slash commands and pattern databases with hunt templates for 58 web vulnerability classes (XSS, SQLi, SSRF, IDOR) plus recon/OSINT and reporting workflows. Includes authorization gates and excludes internal AD, C2 and post-exploitation.
- Open ↗InstaVM Security Skillsdual-uselicence
Agent skills for Claude Code, Gemini CLI or other Skills/MCP agents that analyze mitmproxy-captured traffic for vulnerability classes such as IDOR, SSRF, SQLi, auth and secrets, distilled from disclosed HackerOne bug bounty reports.
Labs & practice targets
- Open ↗Altoro Mutual (AltoroJ)hosted
Classic sample banking J2EE web app demonstrating real-world application security issues; also self-hostable.
- Open ↗
Self-contained Java/JSP vulnerable app aimed at pentest beginners, covering XSS, SQLi and hidden content.
- Open ↗
Educational PHP/MySQL environment teaching common web/PHP vulnerabilities alongside their mitigations.
- Open ↗
Purposely insecure PHP blog simulating a novice's code, used to teach manual and automated vulnerability detection and remediation.
- Open ↗
Ruby on Rails application from the Broken Web Applications (BWA) project for local security testing.
- Open ↗
Single-file Python vulnerable web app (<100 lines) supporting most popular web vulnerability classes for education.
- Open ↗
Damn Vulnerable Java EE application for security testing, runnable via Docker Compose, Maven Jetty or a Tomcat WAR.
- Open ↗
Damn vulnerable Node.js app with varying difficulty levels for practicing common web vulnerabilities.
- Open ↗
Node/Express/Sequelize app demonstrating the OWASP Top 10 with a developer security guidebook and a fixes branch.
- Open ↗
Python app (inspired by DVWA) with session fixation, SQLi, stored XSS and weak-password vulnerabilities.
- Open ↗
Short PHP web app whose vulnerabilities naive scanners fail to detect — useful for testing scanner depth.
- Open ↗
PHP/Docker deliberately insecure web application for security practice.
- Open ↗
Intentionally vulnerable Django app with master and broken branches for learning security testing with ZAP.
- Open ↗
Node/Express/MongoDB app covering OWASP Top 10 injection, NoSQLi and OS command injection for app-security learning.
- Open ↗Google Gruyerehosted
Small Python web app for text snippets/files with intentional XSS, XSRF, information-disclosure, DoS and RCE bugs (Google codelab).
- Open ↗
OWASP Mutillidae II — free PHP web-security training target with 40+ vulnerabilities and broad coverage.
- Open ↗
Node.js/PostgreSQL app with real (not simulated) vulnerable code for benchmarking source-code analyzers and white-box testing.
- Open ↗
Vulnerable e-commerce web app (Next.js/React/Node) for security practice.
- Open ↗
PHP vulnerable web application for security practice.
- Open ↗
PHP/MySQL learning platform where each 'brick' contains a security issue to exploit manually or with tools.
- Open ↗
Deliberately vulnerable Ruby on Rails app with per-version tutorials demonstrating security issues and their fixes.
- Open ↗
Web and mobile app security training platform with lessons and challenges based on the OWASP Top Ten.
- Open ↗
Docker lab examples for the Security Knowledge Framework, correlated to KB IDs and controls (ASVS, NIST) with write-ups.
- Open ↗
Learning platform for common web security flaws with .NET-specific lessons.
- Open ↗
Vulnerable Play (Scala) app demonstrating unvalidated client input trusted and reflected into responses.
- Open ↗
Globo.com collection of many intentionally vulnerable web apps across multiple stacks, each with attack narratives and Docker options.
- Open ↗
Java/Spring Boot app demonstrating OWASP Top 10 and other security vulnerabilities.
- Open ↗
Java/Tomcat/MySQL vulnerable app from the Cyber Security and Privacy Foundation for learning web vulnerabilities and secure coding.
- Open ↗
Minimal Node/Express app demonstrating SQLi and XSS.
- Open ↗
PHP/Docker web vulnerability lab project by Yavuzlar.
- Open ↗
OWASP port of WebGoat to PHP/MySQL — interactive lessons where you exploit each vulnerability to demonstrate understanding.
- Open ↗
Learning resource by Omar Santos bundling many intentionally vulnerable applications in Docker containers for training.
- Open ↗
Deliberately vulnerable health-tech platform (React/Node/Postgres) with an AI chatbot for learning app security and ethical hacking.
References
- Open ↗ZAP Community Scriptsactive
A community-maintained collection of scripts and tips for OWASP ZAP (Zed Attack Proxy), organized by category including active scan, passive scan, authentication, encode/decode, HTTP fuzzing, payload generation, and WebSocket testing, written in Python, JavaScript, Kotlin, Ruby and others. Scripts are installable via the ZAP Marketplace and released under Apache 2.0.