
WebGoat
Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Some good resources for getting started with application security

Deliberately vulnerable Flask web application with 22 security flaws across 3 difficulty levels for hands-on penetration testing and web security…

The vulnerable application that will teach you how to hack WebSockets

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Simple flask application to implement an intentionally vulnerable web app to demo CVE-2023-2822.

A vulnerable version of Rails that follows the OWASP Top 10

Educational environment for LTAT.04.022 Homework 4.

intentionally vuln web Application Security in django

An intentionally designed broken web application based on REST API.

LazyWeb is a demonstration web application designed to showcase common server-side application vulnerabilities. Each vulnerability is categorized…

Example Vulnerable .NET HTTP Remoting

Vulnerable Python Application To Learn Secure Development

PoC for a Critical stack-based buffer overflow in GNU libextractor ≤ 1.14. A malicious .doc file triggers an unbounded VLA allocation causing…

Intentionally vulnerable Next.js application demonstrating CVE-2025-29927 authentication bypass via middleware WAF evasion. Designed for security…

Evidence first autonomous web security testing for controlled, authorized targets. With reproducible labs, audit trails, reports, and XBEN…

A Microservices-based framework for the study of Network Security and Penetration Test techniques