This repository contains a collection of real-world web applications with known security vulnerabilities. The purpose of this collection is to support education, training, and security research.
These applications are insecure by design — not intentionally, but due to common mistakes found in real projects. Do not expose them to the internet. They must only be run in isolated, local environments.
- Security training and workshops
- Analysis of common implementation flaws
- Practice for penetration testing and code auditing
This code is provided for educational purposes only. The maintainers take no responsibility for any misuse.