
mutillidae
OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Cross-site scripting labs for web application security enthusiasts

A deliberately vulnerable web application for learning web application security.

Web application with vulnerabilities found in real cases, both in pentests and in Bug Bounty programs.

Discover hidden debugging parameters and uncover web application secrets

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

A web application vulnerable to CVE-2020-14343 insecure deserialization leading to command execution in PyYAML package.

WVCTF or WebVulnCTF is a gamified web platform which promotes training in pentesting and web application development security in an entertaining way.…

Django-based CTF blog platform with integrated CVE-2021-35042 exploit tool for learning web application security and vulnerability exploitation.

Capture-the-flag challenge for Ekoparty 2020 featuring a Flask web application with security vulnerabilities to exploit. Designed for hands-on…

Open-source web application security challenge platform with auto-approved registration, SQL dump generation, and Docker deployment for hands-on…

Step-by-step walkthrough for exploiting Subrion CMS via CVE-2021-2220 on an OffSec lab machine, covering web application exploitation and flag…

Deliberately vulnerable .NET web application for learning common web security flaws through hands-on exercises covering XSS, SQL injection, and other…

Intentionally vulnerable web application for security training, CTF competitions, and testing security tools. Covers OWASP Top Ten vulnerabilities…

Docker-based lab demonstrating CVE-2017-8291 (GhostButt) exploitation via Python PIL/Pillow EPS image processing, with a vulnerable web application…