OWASP Vulnerable Web Applications Directory

An OWASP production project

A comprehensive registry of known vulnerable web and mobile applications for legal security testing and training.

Thanks to our contributors.

Browse & search

Discover apps with basic filters or advanced search options.

Search type

Search by app name or author, with up to one collection, one technology, and one category filter.

-

Loading…

About VWAD

The OWASP Vulnerable Web Applications Directory (VWAD) Project is a well-maintained registry of vulnerable web and mobile applications available for security professionals. Use them for training, tool testing, and practice in realistic environments.

Applications are classified as Online, Offline, Mobile, Containerized (Docker, VMs, ISOs), or Platform.

Contributors

Thanks to everyone who has contributed to the directory and this site across the project repositories.

Loading…