
crAPI
Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Professional vulnerability assessment of a multi-VLAN enterprise network (student21.local). Confirmed Stored XSS on WebGoat (HIGH, 16) via OWASP ZAP…

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how…

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

MARA is a Mobile Application Reverse engineering and Analysis Framework. It is a toolkit that puts together commonly used mobile application reverse…

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists

An installable desktop variant of OWASP Threat Dragon

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

An open source threat modeling tool from OWASP

Executable security regression testing for agentic applications and MCP-integrated systems.

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory