
Developer-focused knowledge base of application security vulnerabilities with insecure vs secure code examples, prevention guidance, and OWASP/CWE mappings across languages and frameworks.
VulnVault is a practical, developer‑first knowledge base of common and critical application security vulnerabilities, covering the full lifecycle from code to build, infrastructure, and deployment.
It provides clear explanations, realistic insecure vs secure code examples, and actionable guidance across multiple programming languages and frameworks to help teams build secure applications by default.
🎯 Goal: Uplift the organisation’s application security posture by making secure coding understandable, accessible, and repeatable.
Most security guidance is either:
VulnVault bridges that gap by:
This repo is designed to be used by:
VulnVault is organised by vulnerability category, not by tool or standard.
Each vulnerability typically includes:
Examples are written using realistic application patterns, not contrived snippets.
Current coverage includes (and is expanding):
Each example contrasts ❌ insecure and ✅ secure implementations side‑by‑side.
String query = "SELECT * FROM users WHERE username = '" + username + "'";
Why this matters: Untrusted input is directly concatenated into the query, allowing attackers to manipulate SQL logic.
String query = "SELECT * FROM users WHERE username = ?";
PreparedStatement ps = connection.prepareStatement(query);
ps.setString(1, username);
ResultSet rs = ps.executeQuery();
📚 Learning & Reference Use as a secure coding handbook during development.
🔍 Code Reviews Link relevant VulnVault pages directly in PR comments.
🧪 Security Testing Validate whether findings from SAST, DAST, or pentests are exploitable.
🎓 Training & Onboarding Use examples to upskill new hires and junior developers.
🛡 AppSec Program Enablement Align guidance with internal standards, threat models, and risk appetite.
Contributions are welcome and encouraged. You can contribute by:
Guiding principles for contributions:
VulnVault intentionally focuses on:
This is not a vulnerability scanner—it’s a security enablement asset.
The examples in this repository are for educational purposes only. Do not deploy insecure examples to production systems.
This project is licensed under the MIT License. See the LICENSE file for details.
Inspired by real‑world security reviews, penetration tests, and lessons learned from building and securing production systems.
🔐 Build secure software. By design.