The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.
-
Updated
Feb 19, 2026 - JavaScript
The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.
Hackademy is a Vulnerable Web Application, Made to practice and study the web security in depth from the Back-end perspective and understands how vulnerabilities get to arise
WebGoat is a deliberately insecure application
Add a description, image, and links to the vulnerable-web-application topic page so that developers can more easily learn about it.
To associate your repository with the vulnerable-web-application topic, visit your repo's landing page and select "manage topics."