
owasp-scs
OWASP Smart Contract Security (SCS) Project

OWASP Smart Contract Security (SCS) Project

Vulnerable app with examples showing how to not use secrets

Source code for the Binaries of OWASP WrongSecrets

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

Web and mobile application security training platform

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…


Community-led OSINT verification standard with testable requirements, acceptance tests, JSON schemas, and assessment formats for safer, interoperable…

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

Web application security assessment of DVWA using OWASP ZAP — vulnerability scanning, RCE (CVE-2012-1823) analysis, and remediation report.

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…
