OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
-
Updated
Sep 18, 2026 - TypeScript
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.
open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.
vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.
Burp Suite extension (BApp Store) that finds backup, old, temporary and unreferenced files leaking sensitive data on web servers. OWASP WSTG-CONF-04.
A simple PHP application to learn SQL Injection detection and exploitation techniques.
Burp Suite extension that finds exposed admin panels and login pages of web applications and infrastructure. 1,000+ payloads, OWASP WSTG-CONF-05.
Dockerized PHP lab with XSS (cross-site scripting) challenges and filter-bypass examples for practising web exploitation.
Python and Django implementation of the OWASP RailsGoat project
Dockerized PHP lab with file upload vulnerability challenges: bypass upload filters to achieve remote code execution.
A Laravel package that helps developers ensure their applications follow OWASP Top 10 security guidelines.
Powerful, beautiful, fast & functional multi threaded static web server in rust with a template engine with multipart support
Aplicación vulnerable al OWASP Top 10 2021, para el Curso de OWASP Top 10: Riesgos en Aplicaciones.
PoC for CVE-2021-45897
Vulnerable FastAPI in reference to Opensource Web Application Security Project (OWASP) TOP 10: 2021
PoC for CVE-2022-23940
A BOLA/IDOR access-control confirmation engine — code adjudicates every verdict, not just the model, with a reproducible evidence chain.
OWASP Automated Threats (OATv2) concise guide, highlighting real-world exploit methods, attacker motives and associated bug bounty values.
Vulnerable AI applications and hands-on labs for learning the OWASP Top 10 for Large Language Model Applications.
Praktek API Penetration Testing menggunakan Owasp crAPI
To associate your repository with the owasp-top-ten topic, visit your repo's landing page and select "manage topics."