http://HOST:3000
nodejsexpressangularrestsqlite
owasp-top-10sqlixssbroken-access-controljwt-forgeryssrfxxercenosql-injectioninsecure-deserialization
Built-in challenge tracker at /#/score-board enumerates every intended vuln with difficulty. REST API at /api and /rest. NODE_ENV=unsafe so file-write/RCE challenges are live.
http://HOST:8086
phpmysqlapache
sqliblind-sqlixsscsrfcommand-injectionfile-inclusionfile-uploadbrute-forcecaptcha-bypass
creds: admin / password
first run: Log in (admin/password), open /setup.php, click 'Create / Reset Database'.
One page per vuln class; DVWA Security level (low/medium/high/impossible) set at /security.php controls exploitability. Source of each page viewable in-app ('View Source').
http://HOST:8082/WebGoat
javaspring-boot
sqlixxejwtpath-traversalssrfinsecure-deserializationxsscsrfidorvulnerable-components
creds: register any account / -
first run: Register a user at /WebGoat/registration.
Structured lessons; each has explicit success criteria the app checks and marks complete. Progress JSON at /WebGoat/service/lessonoverview.mvc once authenticated.
http://HOST:8083
phpmysqlopenldapapache
sqlixssxxecommand-injectionlfi-rfildap-injectionhtml-injectionjwtcsrfclick-jackingcbc-bit-flipping
creds: admin / adminpass
first run: Open /set-up-database.php once to build/seed the schema (also fixes 'Database offline' banner).
OWASP-2017/2013 mapped menu; per-page hint system with 5 levels. 'Toggle Security' switch (0=insecure,1=fair,2=secure) at top bar. Bomb icon = hackable.
http://HOST:8084
phpmysqlapache
sqlixssssrfxxercelfi-rfildap-injectionxpath-injectionmail-header-injectionheartbleedshellshockhtml5-issues
creds: bee / bug
first run: Visit /install.php and click 'here' to initialise the database.
~100 pre-catalogued bugs selectable from a dropdown, each with 3 security levels (low/medium/high). Full bug list on the project site / choose-bug page.
http://HOST:8085
phpmysqlapache
sqlixssos-command-injectionxxeunrestricted-file-uploadssrfserver-side-template-injectioninsecure-cryptosession-issuescsrfidor
creds: admin / admin
first run: Open /setup/ and click 'submit' to create and seed the database.
One challenge per vuln class listed in the left nav; no difficulty toggle (always exploitable).
http://HOST:9091/VulnerableApp/
javaspring-boot
sqlixsscommand-injectionxxessrfpath-traversalopen-redirectcrlf-injectionjwtdeserialization
Built to benchmark DAST tools: each endpoint is a clean, isolated, deterministic test case. Machine-readable case list at /VulnerableApp/ScannerService/scanners and /VulnerableApp/threat/all.
http://HOST:5001
pythonflasksqlitejwt
api-broken-object-level-authapi-broken-authexcessive-data-exposuremass-assignmentsqliunauthorized-password-changeuser-enumeration
creds: admin / pass1, name1 / pass1
first run: GET /createdb to (re)initialise and seed the database.
Root '/' returns JSON describing vulnerable vs secure mode (vulnerable=1 here). OpenAPI spec at /ui and openapi_specs/openapi3.yml. Endpoints map 1:1 to OWASP API Top 10 items.
http://HOST:5013
pythonflaskgraphenegraphqlsqlite
graphql-injectionbatching-attacksdos-via-nested-queriesdeep-recursionos-command-injectionssrfxssbroken-authorizationgraphql-introspectioncsrf
creds: admin / password
Difficulty toggle (Easy/Hard) at /difficulty controls introspection & field suggestions. GraphiQL IDE at /graphiql, raw endpoint at /graphql. Solutions documented in the project's SOLUTIONS.md.
http://HOST:8888
javaspring-bootpythondjangogolangnodejspostgresmongodbmicroservices
api-bolaapi-broken-authapi-bflamass-assignmentssrfnosql-injectionsqlijwt-algorithm-confusionimproper-inventory-mgmtunauthenticated-accessjwt-weak-key
creds: register in-app / -
first run: make thirdparty && make crapi-up (first boot pulls ~8 images and seeds DBs; allow a few minutes).
Realistic connected-car app. Each challenge in the project's checklist targets a specific endpoint; upstream repo carries a full solutions/hints doc.
http://HOST:3001/swagger
nodejsnestjspostgreskeycloak
sqlixxessrfpath-traversalxssjwtoauth-issuesmass-assignmentopen-redirectcss-injectionldap-injectionvulnerable-componentssecrets-exposure
creds: admin / admin
first run: make thirdparty && make brokencrystals-up (pulls app + Keycloak + a small Ollama model image).
API-first: the prebuilt brightsec/brokencrystals image serves the NestJS API + Swagger UI at /swagger (not the React SPA). Almost every vuln is an /api/* endpoint; leaked config/secrets at /api/config. Upstream README has the full vuln table.
http://HOST:4000
nodejsexpressmongodb
injectionbroken-authxssbroken-access-controlsecurity-misconfigurationsensitive-data-exposurecsrfinsecure-deserializationssjs-injectionregex-dos
creds: admin / Admin_123
first run: Fetched by scripts/fetch-thirdparty.sh; compose builds the app and seeds Mongo.
Each OWASP Top 10 item has a dedicated tutorial page describing the exact exploit and the fix.
http://HOST:8090/docs
pythonfastapipostgresjwt
api-broken-authapi-bolaapi-bflamass-assignmentsqlios-command-injectionssrfjwt-issuesrate-limit-bypassidor
creds: register via /auth/register / -
first run: Fetched by scripts/fetch-thirdparty.sh; compose builds the API and migrates Postgres.
CTF-style: repo ships numbered challenges under /challenges each with a description, hints, and a reference solution.