A comprehensive vulnerable web application designed for security education and penetration testing practice.
Explore vulnerabilities in login, registration, OTP verification, and password reset mechanisms.
Practice exploiting IDOR, privilege escalation, and missing access controls.
Test SQL injection, command injection, and file inclusion vulnerabilities.
Discover reflected, stored, and SVG-based XSS vulnerabilities.
Exploit weak JWT implementations and algorithm confusion.
Manipulate sessions, hijack cookies, and exploit session fixation.
This application is designed for educational purposes. Use it to: