
dynast-bench
A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

Intentionally vulnerable Drupal 7.57 lab for reproducing CVE-2018-7600 (Drupalgeddon2) in a Docker container, with an installer script and PHP…

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

This repository contains a number of insecure self-hosted applications that allows interested security engineers to test vulnerabilities found by…

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…

Intentionally vulnerable Next.js application demonstrating CVE-2025-55182 RCE via unsafe deserialization in React Server Components. Includes exploit…

React2Shell (CVE-2025-55182) – An intentionally vulnerable Next.js application created for educational and research purposes.

Dockerized Spring Boot service intentionally vulnerable to Log4Shell (CVE-2021-44228) for testing detection tools, payloads, and exploit capabilities…

CVE-2021-3007 Vulnerable Test Environment - Laminas/Zend Framework Deserialization RCE

Intentionally vulnerable Next.js app for CVE-2025-55182 security research and CTF challenges

Docker-based lab for detecting and exploiting CVE-2025-55182 (React2Shell RCE) in Next.js/React Server Components, with pre-configured vulnerable…

A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass

Hands-on AI security learning platform with intentionally vulnerable LLM applications. Explore OWASP Top 10 for LLMs through interactive pizza shop…

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

An intentionally vulnerable webapp to get your hands dirty with CVE-2022-42889.