Three intentionally vulnerable web applications for practising OWASP Top 10 attack techniques.
PHP, Node.js (Express), and ASP.NET Core variants — each covering SQL injection, XSS,
broken auth, IDOR, path traversal, and more.
⚠
FOR LOCAL / ISOLATED TESTING ONLY.
These applications are intentionally vulnerable by design.
Never expose them to the internet or a shared network. Run only in a controlled environment.