OWASP Vulnerable Web Applications Directory

An OWASP production project

A comprehensive registry of known vulnerable web and mobile applications for legal security testing and training.

OWASP Juice Shop

Probably the most modern and sophisticated insecure web application. For use in security trainings, awareness demos, CTFs and as a guinea pig for security tools. Encompasses vulnerabilities from the entire OWASP Top Ten along with many other security flaws found in real-world applications. Written in Node.js, Express and Angular.

Collections offline online container
Technology TypeScript JavaScript Angular Node.js Express
Categories CTF Free-form Single-player
Author OWASP
Stars 13055 stars
Last contribution Apr 14, 2026 < 1mo

← Back to directory