OWASP Vulnerable Web Applications Directory

An OWASP production project

A comprehensive registry of known vulnerable web and mobile applications for legal security testing and training.

vAPI

Vulnerable Adversely Programmed Interface: self-hostable API that mimics OWASP API Top 10 through exercises. PHP/Laravel; Postman collection and docs at http://localhost/vapi/.

Collections offline
Technology PHP MySQL Laravel
Categories Free-form Single-player
Author Tushar Kulkarni
Stars 1337 stars
Last contribution Jan 10, 2025 < 2y

Notes

Import vapi.sql into MySQL; configure vapi/.env. docker-compose up -d or php artisan serve.

← Back to directory