Skip to content
VulnerableApp
Vulnerability Scanning
A modular, deliberately vulnerable web application for benchmarking and testing security scanners in repeatable, automated environments
Java
·
Latest 2.1.0 · 24d ago
Security brief →
Features
-
Enables scanner benchmarking against known vulnerability patterns
-
Provides a modular design for adding new security scenarios without altering core services
-
Supports deterministic, repeatable regression testing across releases and environments
-
Simulates realistic modern web‑app attack surfaces
-
Offers both Docker‑compose deployment and standalone JAR execution
No immediate action
2.1.0
New feature
·
Modules, Challenge Cards, Infrastructure, Docs, Contributors
No immediate action
2.0.1
Mixed
·
LLMForge + IDOR + Clickjacking
No immediate action
2.0.0
Mixed
·
LLMForge + new vulnerabilities
Review required
1.13
Breaking risk
·
Auth
RCE / SSRF
JWT header handling + translations + Docker fix
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
About
Languages
Java
·
JavaScript
·
HTML
View on GitHub
Install & Platforms
Install via
docker
docker-compose
binary
Search tools, categories, lists, and users
Use ↑↓ to navigate, Enter to open, Esc to close
No results for ""
⌘K to open
↑↓ navigate
⏎ open