Skip to content

VulnerableApp

v2.1.0 Feature

This release adds 8 notable features for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

security burpsuite css java javascript learn-security
+9 more
owasp owasp-zap payload-testing practice-hacking spring-boot test-vulnerability-scanning-tools vulnerability vulnerability-scanning vulnerable-application

Summary

AI summary

Broad release touches 🛡️ New Vulnerability Modules, 🏗️ Infrastructure & Tooling, 📚 Documentation & Community, and @luks-santos.

Full changelog

🎉 VulnerableApp 2.1.0

A major release packed with new vulnerability modules, infrastructure hardening, and strong community growth — 18 new contributors joined this cycle!

🛡️ New Vulnerability Modules

  1. Authentication Vulnerability Module — full implementation, including a new "Low Iteration Password Hashing" challenge level (@ayash911, @aryankshl)
  2. Cache Poisoning — brand new vulnerability class added (@luks-santos)
  3. IDOR Module — enhanced with secure token handling (@Etoile-Bleu)
  4. Cryptographic Failures — module enhancements (@aashpis)
  5. Open Redirect — phishing-aware levels added (Levels 9, 10, 11) (@StevenTaing2, @Jhalak19-Sethi, @polcm005), plus payload/message-key improvements (@An16og)
  6. Clickjacking — Challenge mode support added (@Clark1945)
  7. Authentication — Challenge mode added (@luks-santos)

🧩 New Framework: Challenge Cards

A new @ChallengeCard annotation system was introduced for structured, gamified vulnerability challenges (@aryankshl) — now rolled out across multiple modules.

🏗️ Infrastructure & Tooling

  1. Docker-based dashboard added (@harveenkaur2912)
  2. Scanner benchmark framework for DAST/SAST coverage (@MukulGhare)
  3. llmforge build migrated to a Docker Hub image for easier setup (@aruzaphoenix)
  4. @Profile("public"/"unsafe") safeguards added across vulnerability controllers to separate safe/unsafe deployment modes (@prajp98)
  5. Extra scanner path configuration support (@nguyenvulong)
  6. @antriksh-9 — Enhanced the first-time contributor workflow
  7. @MixhizoR — Added secure variants to Http3xxStatusCodeBasedInjection annotations

📚 Documentation & Community

  1. New organizational usage documentation added (@CharanTeja-6825)
  2. University of Adelaide added to the usage showcase (@aruzaphoenix)
  3. Design documentation grammar and formatting cleanup (@muhammadrehanazam)
  4. Facade schema population work (@saurabhkushwaha438)

📊 By the Numbers

~66 merged PRs
21 contributors
Continued momentum on infra hardening, new challenge types, and onboarding polish

Full changelog: https://github.com/SasanLabs/VulnerableApp/compare/2.0.1...2.1.0

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track VulnerableApp

Get notified when new releases ship.

Sign up free

About VulnerableApp

All releases →

Beta — feedback welcome: [email protected]