The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.
-
Updated
Feb 5, 2026 - JavaScript
The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.
Zero trust. Zero security. Total exposure. A deliberately vulnerable health tech platform with AI Chatbot for learning about application security and ethical hacking. It contains vulnerabilities from OWASP top 10 Web, API and AI/LLM Security Vulnerabilities. Highly vulnerable, never use in production.
SSJS Web Shell Injection Case
⛔️deprecated and replaced by https://github.com/marmicode/websheep
mini-juice-shop
An intentionally vulnerable web application built with React & Node.js for cybersecurity education, penetration testing practice, and security scanner development.
Web Apps // Web Dev Projects // Intermediate Learning Web Apps
Add a description, image, and links to the vulnerable-web-app topic page so that developers can more easily learn about it.
To associate your repository with the vulnerable-web-app topic, visit your repo's landing page and select "manage topics."