
open-sammy
Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10…

This is a defunct code base. The project is located at: https://github.com/WebGoat

Pen Test Report Generation and Assessment Collaboration

IoTGoat is a deliberately insecure firmware based on OpenWrt.

OWASP Passfault evaluates passwords and enforces password policy in a completely different way.

Automated Web Vulnerability Assessment of DVWA using OWASP ZAP to identify and analyze critical security flaws like Remote Code Execution…

The OWASP Mobile Application Security Project website is the central hub for industry-leading standards, guides, and resources—helping developers and…

A deliberately vulnerable web application for learning web application security.


AzureGoat : A Damn Vulnerable Azure Infrastructure

OWASP enumeration of common security and privacy weaknesses in mobile applications, serving as a reference bridging the MASVS verification standard…

Penetration tests guide based on OWASP including test cases, resources and examples.

*This project is no longer maintained* OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and…

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

OWASP top 10 security risks for audio and video communications, documenting common vulnerabilities and threats in modern real-time communication…

Curated collection of bug bounty writeups covering OWASP Top 10 vulnerabilities, including XSS, SQLi, SSRF, and RCE, for educational learning and…

This is a container of web applications that work with OWASP Bug Bounty for Projects