


A deliberately vulnerable web application for learning web application security.

This is a defunct code base. The project is located at: https://github.com/WebGoat

HoneySAP: SAP Low-interaction research honeypot

Advanced HTTP fingerprinting PoC

This is a container of web applications that work with OWASP Bug Bounty for Projects

Apisix系列漏洞:未授权漏洞(CVE-2021-45232)、默认秘钥(CVE-2020-13945)批量探测。

Official repository for the AppSecDC 2019 conference, hosting presentation materials, resources, and curated content from the OWASP AppSecDC event.

Community-driven project providing guidance and resources to improve browser security, including best practices and educational materials for…

Silent dependency injection through AI documentation pipelines. 240 isolated Docker runs proving Context Hub's zero-sanitization MCP server lets…

SQL Injection in 3CX CRM Integration

Spring-Cloud-Gateway-CVE-2022-22947

OWASP tool for systematic threat modeling using the Model Context Protocol to identify and mitigate security risks in software architecture.

Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation

Interactive demo for CVE-2023-45857 (axios XSRF token bypass). Step-by-step guide to reproduce the vulnerability in a controlled dev container…

Magical Addons For Elementor <= 1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery

Proof-of-concept exploit for CVE-2026-21876 demonstrating multipart charset bypass of OWASP CRS WAF in Flask, ASP.NET, and Spring Boot applications.

Reproducer for CVE-2026-46588: Apache Camel camel-couchdb CouchDb* header injection (operation confusion) subverting a write-only endpoint into read…