Vulnerable webapp testbed
-
Updated
May 11, 2016 - Java
Vulnerable webapp testbed
SQL injection testbed designed for sqlmap practice (MySQL backend)
Vulnerable REST based PHP webservice deployed in Docker
VWA (vulnerable web applications) for SSJI, implemented in NodeJS and ExpressJS
TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
Intentionally vulnerable JavaScript Code Snippets which are intended to benchmark Static Application Security Testing tools.
A modern, intentionally vulnerable iOS app for learning mobile penetration testing.
VaultPay is scaffolded—a modern wallet app with all ten 2024 risks planted and cross-mapped to MASVS v2.1.0.
A deliberately vulnerable web application exhibiting a simple password exposure vulnerability.
Intentionally vulnerable GitHub Actions fixtures for Grafter security training
[INTENTIONALLY VULNERABLE - Mithras demo] Programme entitlement and access-token service.
GlassHouse is a collection of intentionally vulnerable applications designed to help students, developers, and security professionals learn about common web vulnerabilities, their exploitation, and how to fix them.
Intentionally vulnerable GitHub Actions fixtures for Grafter security training
A deliberately vulnerable web application exhibiting an unrestricted file upload vulnerability.
Intentionally insecure demo app for the Bolt IoT Agentic Programming Training course. Students audit and patch five planted client-side vulnerabilities using AI coding agents. Do NOT deploy publicly or use with real data.
Intentionally vulnerable GitHub Actions fixtures for Grafter security training
Intentionally vulnerable GitHub Actions fixtures for Grafter security training
Sistema de notas propositalmente vulnerável para educação em segurança cibernética e testes de penetração - contém 12+ vulnerabilidades web intencionais (SQL Injection, XSS, Path Traversal, Command Injection, etc.)
A deliberately vulnerable web application exhibiting a HTML injection vulnerability.
Intentionally vulnerable GitHub Actions fixtures for Grafter security training
To associate your repository with the intentionally-vulnerable topic, visit your repo's landing page and select "manage topics."