
OWASPBugBounty
This is a container of web applications that work with OWASP Bug Bounty for Projects

This is a container of web applications that work with OWASP Bug Bounty for Projects

IoTGoat is a deliberately insecure firmware based on OpenWrt.

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

Automated Web Vulnerability Assessment of DVWA using OWASP ZAP to identify and analyze critical security flaws like Remote Code Execution…


A deliberately vulnerable web application for learning web application security.

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how…

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

Lab report analyzing CVE-2025-68613 expression injection in n8n, demonstrating sandbox escape via crafted payloads to access sensitive server files,…

The dependency-check repository has moved:

AI IR Overlay™ — practical incident response framework for AI agents in production. Built on NIST SP 800-61 r3, mapped to NIST AI RMF, NIST CSF 2.0,…

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

AzureGoat : A Damn Vulnerable Azure Infrastructure

Minimal PoC and Docker container demonstrating a WAF bypass in OWASP ModSecurity CRS via multipart charset handling, leading to XSS payload delivery.