OWASP Vulnerable Web Applications Directory

An OWASP production project

A comprehensive registry of known vulnerable web and mobile applications for legal security testing and training.

Damn Vulnerable Java Application (DVJA)

Damn Vulnerable Java (EE) Application for security testing and learning. Run via Docker Compose (http://localhost:8080), Maven Jetty, or deploy WAR to Tomcat.

Collections container offline
Technology Java Maven MySQL Docker
Categories Free-form Single-player
Author Appsecco
Stars 149 stars
Last contribution May 4, 2020 2y +

Notes

Requires Java 1.7+, Maven 3.x, MySQL. Configure database in src/main/webapp/WEB-INF/config.properties; import db/schema.sql.

← Back to directory