
OWASPBugBounty
This is a container of web applications that work with OWASP Bug Bounty for Projects

This is a container of web applications that work with OWASP Bug Bounty for Projects

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Professional vulnerability assessment of a multi-VLAN enterprise network (student21.local). Confirmed Stored XSS on WebGoat (HIGH, 16) via OWASP ZAP…

Apache Real Time Logs Analyzer System

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how…

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

OWASP IoT Security Verification Standard (ISVS)

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

German OWASP Day conference site & presentation archive

OWASP VBScan is a Black Box vBulletin Vulnerability Scanner

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Maryam: Open-source Intelligence(OSINT) Framework

OWASP Web Recon & Directory Discovery Platform

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.