OWASP VulnerableApp

Break it. Scan it. Reproduce it. Benchmark against it. Improve it.

OWASP VulnerableApp is a modular deliberately vulnerable application designed primarily for validating and benchmarking security scanners through reproducible test scenarios, while also supporting learning and experimentation.

VulnerableApp Docker Pulls
150k
VulnerableApp-Facade Docker Pulls
50K
Contributors
130

About OWASP VulnerableApp

Project Leaders

Karan Preet Singh Sasan

Project Lead

EmailLinkedIn

Project Information

Lab Project
Classification
Other
Language
Java
License
Apache License 2.0
Latest Version
2.1.0
Contributors
96
GitHub Stars
467
Downloads
4758
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.