node-api-goat
Simple Express.js REST API intentionally containing insecure code paths and vulnerable endpoints for testing and learning.
An OWASP production project
A comprehensive registry of known vulnerable web and mobile applications for legal security testing and training.
Simple Express.js REST API intentionally containing insecure code paths and vulnerable endpoints for testing and learning.