OWASP Vulnerable Web Applications Directory

An OWASP production project

A comprehensive registry of known vulnerable web and mobile applications for legal security testing and training.

Security Shepherd

Web and mobile application security training platform designed to foster and improve security awareness. Presents security risk concepts in lessons followed by challenges; utilizes the OWASP Top Ten as a challenge test bed. Real vulnerabilities with dampened impact. Supports CTF, Open Floor, and Tournament modes; highly configurable for single user, classroom, or online competition.

Collections offline
Technology Java
Categories CTF Guided lessons Multi-player Single-player
Author OWASP
Stars 1445 stars
Last contribution May 10, 2026 < 1mo

← Back to directory