Skip to content
#

vulnerable-app

Here are 77 public repositories matching this topic...

vucsa

Vulnerable Client-Server Application (VuCSA) is made for learning how to perform penetration tests of non-http thick clients. It is written in Java (with JavaFX graphical user interface) and contains multiple challenges including SQL injection, RCE, XML vulnerabilities and more.

  • Updated Sep 9, 2023
  • Java

Deliberately vulnerable MCP server (aka MCP Goat) for security training — 26 challenges across 4 difficulty levels (incl. a secure reference), a victim-agent harness, and one-command Docker deploy. Practice penetration testing against the Model Context Protocol.

  • Updated Aug 17, 2026
  • TypeScript
voltmart-pentest-lab

Self-hosted Dockerized pentest lab: five intentionally-vulnerable apps (store, bank, finance, SaaS + a dedicated AI/LLM lab) — 280+ vulns across OWASP Top 10 & the full LLM Top 10. The AI is a built-in deterministic offline engine: NO model, NO API key. A modern DVWA / Juice Shop alternative.

  • Updated Jun 20, 2026
  • PHP

Add this topic to your repo

To associate your repository with the vulnerable-app topic, visit your repo's landing page and select "manage topics."

Learn more