
WSGoat
The vulnerable application that will teach you how to hack WebSockets

The vulnerable application that will teach you how to hack WebSockets

A comprehensive full-lifecycle penetration testing project on Joomla 4.2.5 exploiting CVE-2023-23752 inside a Dockerized lab environment

Dockerized exploit lab and script for CVE-2026-19478, a critical unauthenticated GitLab GraphQL code injection enabling arbitrary Ruby method calls,…

Local lab simulating CVE-2026-29000 JWT/JWE authentication bypass in pac4j-jwt. Provides login, token forging, and dashboard APIs for practicing web…

Automated exploit for CVE-2022-42889 (Text4Shell) with a vulnerable Dockerized app for testing and manual exploitation guidance.

Dockerized environment to reproduce CVE-2019-16113, a directory traversal and RCE vulnerability in Bludit CMS 3.9.2, with PoC for image upload…

Twitter vulnerable snippets

Dockerized labs For Web Expert (OSWE) certification. Preparation for coming AWAE Training ...

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

Dockerized PHP application providing hands-on XSS vulnerability challenges and bypass examples, including WAF, blacklist, and JavaScript validation…

CVE-2022-42889 dockerized sample application (Apache Commons Text RCE)

Dockerized proof-of-concept for CVE-2022-42889 (Text4Shell) with script, DNS, and URL lookup-based RCE payloads for security testing and education.

Proof of Concept for CVE-2025-55182 ("React2Shell"). A fully dockerized environment demonstrating Remote Code Execution (RCE) via insecure…

Vulnerable Dockerized web app exposing RCE, path traversal, hardcoded credentials, and insecure file uploads; an isolated lab for testing security…

Educational repository for learning CVE-2025-55182: a pre-authentication RCE in React Server Components. Includes step-by-step documentation,…

Full-chain reproduction of CVE-2022-36804 (Bitbucket RCE). Includes a Dockerized laboratory, pspy64 monitoring for null-byte injection verification,…

Proof-of-concept exploit for CVE-2026-1357, an unauthenticated arbitrary file upload in WPvivid Backup & Migration leading to remote code execution.…

Dockerized Apache mod_lua lab with a Python PoC reproducing the CVE-2021-44790 multipart boundary buffer overflow for local defensive testing and…