awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com

Deliberately Vulnerable Web Applications

Ranking updated Jun 30, 2026

For a vulnerable web application for security training, the first results are digininja/dvwa (DVWA is a classic deliberately vulnerable PHP/MySQL web application that directly matches this search — it provides a sandbox for practicing OWASP Top 10 exploits with configurable difficulty levels and is widely used for security training and CTF labs), webgoat/webgoat (WebGoat is the classic deliberately insecure web application for security training, covering the OWASP Top 10 with structured lessons, self-hostable via Docker, and including progressive difficulty and built-in hints, making it an ideal fit for this query) and juice-shop/juice-shop. bkimminich/juice-shop and ethicalhack3r/dvwa round out the shortlist. Compare the match explanations and check the project documentation against your requirements.

These open-source projects provide insecure environments for practicing penetration testing and learning web application security vulnerabilities.

Deliberately Vulnerable Web Applications

Find the best repos with AI.We'll search the best matching repositories with AI.
  • digininja/dvwadigininja avatar

    digininja/DVWA

    13,229View on GitHub↗

    DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is

    DVWA is a classic deliberately vulnerable PHP/MySQL web application that directly matches this search — it provides a sandbox for practicing OWASP Top 10 exploits with configurable difficulty levels and is widely used for security training and CTF labs.

    PHPVulnerability TrainingCybersecurity Training LabsPenetration Testing Environments
    View on GitHub↗13,229
  • webgoat/webgoatWebGoat avatar

    WebGoat/WebGoat

    9,160View on GitHub↗

    WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to identify and exploit common web vulnerabilities. It serves as a containerized sandbox that allows for the simulation and experimentation of web-based attacks and penetration testing techniques without risking production systems. The project functions as a learning lab that maps specific insecure coding patterns to structured lessons. It implements simulated server-side flaws to provide a hands-on environment for studying common security vulnerabilities and defensive coding practices.

    WebGoat is the classic deliberately insecure web application for security training, covering the OWASP Top 10 with structured lessons, self-hostable via Docker, and including progressive difficulty and built-in hints, making it an ideal fit for this query.

    JavaScriptVulnerable Web ApplicationsContainer-Based SandboxesCybersecurity Training Materials
    View on GitHub↗9,160
  • juice-shop/juice-shopjuice-shop avatar

    juice-shop/juice-shop

    12,530View on GitHub↗

    Juice Shop is a self-contained web application designed as a platform for cybersecurity education and security training. It functions as a controlled environment containing intentional security flaws, allowing users to practice offensive security techniques and defensive coding practices while tracking their progress through a live scoreboard. The platform serves as an industry-standard benchmark for evaluating the effectiveness and detection accuracy of automated security scanning tools. By hosting a standardized set of known vulnerabilities and common attack patterns, it provides a reliable

    OWASP Juice Shop is a deliberately vulnerable web application that covers a wide range of security flaws (including OWASP Top 10), provides a live scoreboard for CTF-style tracking, supports Docker deployment, and includes progressive challenges with available walkthroughs, making it an ideal platform for security training and penetration testing practice.

    TypeScriptVulnerable Web ApplicationsCybersecurity Training LabsSecurity Benchmarks
    View on GitHub↗12,530
  • bkimminich/juice-shopB

    bkimminich/juice-shop

    0View on GitHub↗

    OWASP Juice Shop is a deliberately insecure Node.js web application that covers the OWASP Top 10 vulnerabilities, supports Docker deployment, offers a scoreboard with progressive challenges, and includes a hint system, making it an ideal flagship for security training and CTF practice.

    Vulnerability TrainingVulnerable ApplicationsVulnerable Systems
    View on GitHub↗0
  • ethicalhack3r/dvwaethicalhack3r avatar

    ethicalhack3r/DVWA

    13,236View on GitHub↗

    DVWA is a vulnerable web application sandbox and PHP security training environment. It serves as a deployable penetration testing target and an OWASP Top 10 lab designed for practicing exploits and simulating common web security vulnerabilities. The application allows users to adjust security difficulty levels to match their skill level and toggle between different SQL database engines to test how various systems handle injection attacks. It includes a mechanism to disable authentication, enabling automated security tools to interact directly with the environment. The project provides capabi

    DVWA is the classic deliberately vulnerable web application for OWASP Top 10 training, with adjustable difficulty levels and Docker support, though it lacks explicit capture-the-flag scoring and built-in walkthroughs — it still squarely fits your search for a legal security practice lab.

    PHPVulnerable Web ApplicationsLanguage-Specific Security TrainingPenetration Testing Frameworks
    View on GitHub↗13,236
  • owasp/nodegoatowasp avatar

    owasp/nodegoat

    2,051View on GitHub↗

    The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.

    NodeGoat is a deliberately vulnerable Node.js web application that covers the OWASP Top 10 risks, perfectly suiting security training and practice, although it does not advertise Docker support, flag-based scoring, or progressive difficulty levels.

    HTMLSecurity EducationVulnerability EnvironmentsVulnerability Training
    View on GitHub↗2,051
  • owasp/securityshepherdOWASP avatar

    OWASP/SecurityShepherd

    1,448View on GitHub↗

    Web and mobile application security training platform

    Security Shepherd is an OWASP intentionally vulnerable web and mobile application training platform, making it a solid fit for security education and penetration testing practice — it covers multiple vulnerability classes and is typically self-hostable.

    JavaVulnerable ApplicationsVulnerable Labs and Apps
    View on GitHub↗1,448
  • owasp/railsgoatOWASP avatar

    OWASP/railsgoat

    923View on GitHub↗

    A vulnerable version of Rails that follows the OWASP Top 10

    Railsgoat is a deliberately vulnerable Rails application that covers the OWASP Top 10 vulnerabilities, fitting the need for legal penetration testing practice, though it lacks some features like flag-based scoring and progressive difficulty.

    HTMLVulnerable Test Targets
    View on GitHub↗923
  • ctfd/ctfdCTFd avatar

    CTFd/CTFd

    6,523View on GitHub↗

    CTFd is a platform for hosting Capture-the-Flag competitions, not a deliberately vulnerable application itself; while it supports flag scoring and Docker deployment, you would need to add separate vulnerable challenges to use it for security training.

    PythonCTF Web FrameworksCTF Challenge Editors
    View on GitHub↗6,523
  • zardus/ctf-toolszardus avatar

    zardus/ctf-tools

    9,434View on GitHub↗

    This project is a security tool installation framework and binary analysis toolkit designed to automate the deployment of research utilities. It provides a containerized security research environment and a system for managing Python and Ruby virtual environments to prevent dependency conflicts on the host machine. The framework distinguishes itself through a structured tool catalog and provisioning scripts that automate the installation of utilities into isolated directories. It utilizes executable symlink mapping to provide a unified command interface and supports the bootstrapping of consis

    This repo is a framework for installing and managing security research tools used in CTF competitions, but it is not itself a deliberately vulnerable application or penetration testing practice lab with the requested features like OWASP Top 10 vulnerabilities, flag-based scoring, or built-in walkthroughs.

    ShellCapture The Flag CompetitionsContainerized Deployments
    View on GitHub↗9,434
  • gallopsled/pwntoolsGallopsled avatar

    Gallopsled/pwntools

    13,271View on GitHub↗

    Pwntools is a Python-based framework designed for rapid prototyping and automation in binary exploitation, reverse engineering, and security research. It serves as a comprehensive toolkit for interacting with local and remote processes, providing the primitives necessary to manage complex exploit workflows and streamline security analysis tasks. The framework distinguishes itself through its specialized capabilities for binary manipulation and automated exploit construction. It includes dedicated utilities for parsing executable file formats, assembling and disassembling machine code, and gen

    Pwntools is a CTF exploitation framework for binary tasks, not a deliberately vulnerable web application — it's a companion tool for participants, not a practice lab.

    PythonCapture The Flag Competitions
    View on GitHub↗13,271
  • rsactftool/rsactftoolRsaCtfTool avatar

    RsaCtfTool/RsaCtfTool

    6,988View on GitHub↗

    RsaCtfTool is an RSA cryptanalysis tool designed to recover private keys from weak public keys and decrypt protected data. It functions as an integer factorization tool and a framework for executing lattice-based attacks. The project differentiates itself by combining database-driven factorization algorithms with specialized mathematical exploits. It includes a suite for lattice reduction to target small exponents and a converter to transform SSH public keys into PEM format for compatibility with other analysis software. The software covers broad capability areas including RSA moduli factori

    RsaCtfTool is a specialized cryptanalysis solver for RSA challenges in CTFs, not a deliberately vulnerable web application or practice lab with OWASP-style vulnerabilities and realistic scenarios.

    PythonRSA CryptanalysisLattice-Based Attack FrameworksLattice-Based Attacks
    View on GitHub↗6,988
Compare the top 10 at a glance
RepositoryStarsLanguageLicenseLast push
digininja/dvwa13.2KPHPGPL-3.0May 30, 2026
webgoat/webgoat9.2KJavaScriptNOASSERTIONJun 15, 2026
juice-shop/juice-shop
12.5K
TypeScript
mit
Feb 21, 2026
bkimminich/juice-shop0———
ethicalhack3r/dvwa13.2KPHPGPL-3.0May 30, 2026
owasp/nodegoat2.1KHTMLApache-2.0Jun 15, 2024
owasp/securityshepherd1.4KJavaGPL-3.0Jun 17, 2026
owasp/railsgoat923HTMLMITJan 28, 2026
ctfd/ctfd6.5KPythonapache-2.0Feb 20, 2026
zardus/ctf-tools9.4KShellBSD-3-ClauseMay 22, 2026

Related searches

  • an automated security scanner for web applications
  • an intentionally vulnerable cloud environment for practice
  • Vulnerable web applications
  • Web App Security and Exploitation
  • a platform for practicing cybersecurity CTF challenges
  • a SQL injection testing tool
  • a phishing simulation platform
  • an open source penetration testing framework