
spring4shell_victim
Intentionally vulnerable Spring app to test CVE-2022-22965

Intentionally vulnerable Spring app to test CVE-2022-22965

Sample Spring Boot application intentionally vulnerable to Log4j2 CVE-2021-45105 for practicing exploitation and understanding infinite loop…

Simple flask application to implement an intentionally vulnerable web app to demo CVE-2023-2822.

Intentionally vulnerable Next.js environment for testing security scanners against CVE-2025-55182, with PoC exploit and detection guidance.

A Java application intentionally vulnerable to CVE-2021-44228

Intentionally vulnerable PHP app with Nginx/PHP-FPM setup for reproducing CVE-2019-11043, including Docker and Kubernetes deployment,…

Intentionally vulnerable Next.js corporate landing page demonstrating CVE-2025-55182, a JSON injection leading to RCE/SSRF via unsafe deserialization…

Target Code + Exploit

Intentionally vulnerable web application demonstrating SQL injection vulnerabilities (CVE-2024-8465) for educational purposes, including…

Educational repository demonstrating XSS vulnerabilities in Django Rest Framework applications. Contains intentionally vulnerable code to teach…

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

Intentionally vulnerable Next.js RSC Docker lab for CVE-2025-55182 (React2Shell) local testing

Intentionally vulnerable Log4j 2.14.1 demo for Sysdig CNAPP scanning (CVE-2021-44228)

Intentionally vulnerable React Server Components lab for studying CVE-2025-55182. Provides a safe environment for security researchers, developers,…

Intentionally vulnerable Next.js environment with PoC exploit and detection templates for CVE-2025-55182 (React2Shell RCE), enabling security testing…

Intentionally vulnerable VM-hosted Java shop — Log4Shell (CVE-2021-44228) workshop lab (EC2 / Azure VM / GCE)

Intentionally vulnerable PHP web app demonstrating SQL injection authentication bypass and unauthorized data disclosure modeled after CVE-2024-8465…

A proof of concept exploit script for CVE-2025-55182