OWASP Foundation Web Respository
-
Updated
Oct 11, 2025 - HTML
OWASP Foundation Web Respository
Intentionally vulnerable Node.js REST API for benchmarking SAST, SCA, and code quality tools. Contains 30 real, functional issues across Critical/High/Medium/Low severities covering SQL injection, command injection, path traversal, IDOR, hardcoded secrets, and more. Not for production use.
Add a description, image, and links to the vulnerable-web-applications topic page so that developers can more easily learn about it.
To associate your repository with the vulnerable-web-applications topic, visit your repo's landing page and select "manage topics."