Vulnerable App

For a more updated list refer to Security Teaching & Practice Solutions

Name
Description
Topic
Platform
Pricing

Collection of exercises that demonstrate attacks on real-world crypto

WebApp

Code

Free

Teaches the basics of serverside web-security.

WebApp

Web Platform

Free

XSS injection game

WebApp

Web Platform

Free

An intentionally vulnerable implementation of Facebook's GraphQL technology, to learn and practice GraphQL Security.

WebApp

Docker

Free

A lab to learn about, and play with, GraphQL queries and mutations, with an emphasis on security.

WebApp

Web Platform

Free

This challenge allows you to experiment with jailbreaks/prompt injection against LLM chat agents that use ReAct to call tools.

GenAI

Web Platform

Free

This is an advanced challenge focusing on multi-chain prompt injection scenarios.

GenAI

Web Platform

Free

Interactive, deliberately vulnerable labs

GenAI, WebApp

Web Platform

Free

Provide the most immersive web-based security simulations and training

iOS, Android, WebApp, GenAI

Web Platform

Free, Paid

Immersive interactive exercises based on real world scenarios

WebApp

Web Platform

Free, Paid

Labs, Courses, and Videos

WebApp, Code Review

Web Platform

Free, Paid

A simple Node.js Express REST app with some OWASP vulnerabilities.

WebApp

Code

Free

A multi-tenant banking API

WebApp

Code, Docker

Free

Intentionaly very vulnerable API with bonus bad coding practices

WebApp

Code

Free

Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

WebApp

Code

Free

Test error based, Blind boolean based, Time based.

WebApp

Code

Free

Last updated