OWASP Vulnerable Web Applications Directory

An OWASP production project

A comprehensive registry of known vulnerable web and mobile applications for legal security testing and training.

NodeGoat

Provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them. Includes a tutorial page and a vulnerable app to exploit and fix.

Collections offline
Technology Node.js MongoDB
Categories Guided lessons Single-player
Author OWASP
Stars 2044 stars
Last contribution Jun 21, 2023 2y +

Notes

Default accounts: admin/Admin_123; user1/User1_123, user2/User2_123. Requires MongoDB (local or Atlas).

← Back to directory