Web Security Training Platform

Master cybersecurity vulnerabilities through hands-on labs designed to challenge and enhance your penetration testing skills.

Vulnerability Categories

Cross-Site Scripting

LAB
Easy Training
Reflected XSS - TutorialRepublic: Web Development Reference Search
LAB
Easy Training
Reflected XSS - GIGW: Government Website Guidelines Portal
LAB
Easy Training
Reflected XSS - RefSeek: Academic & Scientific Search Engine
LAB
Easy Training
Reflected XSS - PubMed: National Library of Medicine Search Builder
LAB
Easy Training
Reflected XSS - BigBasket: Online Supermarket Catalog
LAB
Easy Training
Reflected XSS - Global Site Search Portal
LAB
Easy Training
Reflected XSS - Script Tag Filter Evasion
LAB
Easy Training
Reflected XSS - Multi-Parameter Script Filter Evasion
LAB
Easy Training
Reflected XSS - HTML Tag Blacklist Filter
LAB
Easy Training
Reflected XSS - Path Based
LAB
Medium Training
Reflected XSS - Script & Img Tag Filter
LAB
Medium Training
Reflected XSS - Case-Insensitive Filter Bypass
LAB
Hard Training
Reflected XSS - Less-Than Sign Filter
LAB
Hard Training
Reflected XSS - HTML Tag Filter Bypass
LAB
Easy Training
Reflected XSS - Page Heading
LAB
Easy Training
Reflected XSS - Function Name Filter
LAB
Medium Training
Reflected XSS - Extended Function Filter
LAB
Medium Training
Reflected XSS - Event Handler Filter
LAB
Hard Training
Reflected XSS - Multi-Parameter Filter Evasion
LAB
Hard Training
Reflected XSS - Encoding Bypass Attempts
LAB
Hard Training
Reflected XSS - Mixed Security Parameters
LAB
Hard Training
Reflected XSS - String Concatenation Bypass
LAB
Easy DOM XSS
DOM XSS in document.write sink using source location.search
LAB
Hard Training
Reflected XSS - URL Encoding Context
LAB
Hard Training
Reflected XSS - Search Filter Bypass
LAB
Hard Training
Reflected XSS - Category Filter
LAB
Hard Real World HackerOne #1818163
Reflected XSS - Equifax
LAB
Low Real World HackerOne #751870
Reflected XSS - PUBG
LAB
Low Real World HackerOne #1940245
Reflected XSS - Shopify
LAB
Medium Real World HackerOne #149855
Reflected XSS - Imgur Mobile
LAB
Hard Real World HackerOne #1549206
Reflected XSS - Reddit
LAB
Hard Training
Stored XSS - Forum Discussions (Reddit Clone)
LAB
Hard Training
Stored XSS - Product Reviews (Flipkart Clone)
LAB
Hard Training
Stored XSS - Events & Polls Activity Center
LAB
Hard Training
Stored XSS - Support Center (DigitalOcean Clone)
LAB
Hard Training
Stored XSS - Bug Bounty Platform (HackerOne Clone)
LAB
Hard Training
Stored XSS - Video Streaming Service (Netflix Clone)
LAB
Hard Training
CSP Bypass - Unsafe Inline Scripts
LAB
Hard Training
CSP Protected Page
LAB
Hard Real World HackerOne #485748
Stored XSS - Twitter
LAB
Medium Real World HackerOne #1147433
Stored XSS - Shopify
LAB
Medium Real World HackerOne #1084183
Stored XSS - Acronis
LAB
Hard Real World
Blind XSS - ZAP-Hosting
LAB
Medium Real World HackerOne #1011888
Blind Stored XSS - Informatica
LAB
Hard Training
IMDb: Ratings, Reviews, and Where to Watch the Best Movies & TV Shows
LAB
Hard Training
AniList: Explore, Track, and Discover Anime & Manga
LAB
Hard Training
MilesWeb: Fast, Secure & Reliable Web Hosting Built for Indian Websites
LAB
Hard Training
Censys Search - Internet Intelligence Platform
LAB
Medium Real World HackerOne #474656
DOM XSS - HackerOne
LAB
Medium Real World HackerOne #324303
DOM XSS - MyCrypto
LAB
Hard Real World HackerOne #396493
DOM XSS - Starbucks
LAB
Medium Real World HackerOne #704266
DOM XSS - ForeScout Technologies
LAB
Medium Real World HackerOne #1004833
DOM XSS - Informatica
LAB
Hard Training
Self XSS - via POST Parameter
LAB
Hard Training
Self XSS - POST-Based Reflected XSS
LAB
Hard Training
Self XSS - POST XSS in Input Tag Value
LAB
Hard Training
Self XSS - in Document Title
LAB
Secure Training
Reflected XSS - Cloud Instance Console
LAB
Hard Training
Stored XSS via Profile Bio & Reflected XSS via Search Bar
LAB
Easy Training
PUNISHMENT LAB 1
LAB
Easy Training
PUNISHMENT LAB 2
LAB
Medium Training
PUNISHMENT LAB 3
LAB
Medium Training
PUNISHMENT LAB 4
LAB
Hard Training
PUNISHMENT LAB 5
LAB
Hard Training
PUNISHMENT LAB 6
LAB
Easy Training
PUNISHMENT LAB 7
LAB
Easy Training
PUNISHMENT LAB 8
LAB
Medium Training
PUNISHMENT LAB 9
LAB
Medium Training
PUNISHMENT LAB 10
LAB
Hard Training
PUNISHMENT LAB 11
LAB
Hard Training
PUNISHMENT LAB 12
LAB
Hard Training
PUNISHMENT LAB 13
LAB
Hard Training
PUNISHMENT LAB 14
LAB
Hard Training
PUNISHMENT LAB 15
LAB
Hard Training
PUNISHMENT LAB 16
LAB
Hard Training
PUNISHMENT LAB 17
LAB
Hard Training
PUNISHMENT LAB 18
LAB
Hard Training
PUNISHMENT LAB 19
LAB
Hard Training
PUNISHMENT LAB 20
LAB
Hard Training
PUNISHMENT LAB 21
LAB
Hard Training
PUNISHMENT LAB 22
LAB
Hard Training
PUNISHMENT LAB 23
LAB
Hard Training
PUNISHMENT LAB 24
LAB
Hard Training
PUNISHMENT LAB 25
LAB
Hard Training
PUNISHMENT LAB 26
LAB
Hard Training
PUNISHMENT LAB 27
LAB
Hard Training
PUNISHMENT LAB 28
LAB
Hard Training
PUNISHMENT LAB 29
LAB
Hard Training
PUNISHMENT LAB 30
LAB
Hard Training
PUNISHMENT LAB 31
LAB
Hard Training
PUNISHMENT LAB 32
LAB
Hard Training
PUNISHMENT LAB 33
LAB
Hard Training
PUNISHMENT LAB 34

HTML Injection

LAB
Easy Training
HTML Injection - E-commerce
LAB
Easy Real World HackerOne #3079966
HTML Injection - LinkedIn
LAB
Easy Real World HackerOne #57914
Stored HTML Injection - Romit
LAB
Easy Real World HackerOne #358001
Stored HTML Tag Injection - GitLab
LAB
Medium Real World HackerOne #1374017
HTML Injection - HackerOne

Open Redirect

LAB
Easy Training
Basic URL Parameter Redirect
LAB
Easy Real World HackerOne #504751
Open Redirect - Omise
LAB
Easy Real World HackerOne #311330
Open Redirect - Semrush
LAB
Medium Real World HackerOne #2812583
Open Redirect - Tumblr

Authentication Bypass

LAB
Medium Real World HackerOne #1490470
Admin Auth Bypass - UPS
LAB
Medium Training
OTP Verification Bypass via Response Manipulation
LAB
Medium Training
Phone OTP Bypass via Response Manipulation

No Rate Limiting

LAB
Easy Training
No Rate Limiting
LAB
Hard Real World HackerOne #1708824
Yelp for Business - Missing Rate Limiting on Subscription Form
LAB
Hard Real World HackerOne #1322243
On Running - Missing Rate Limiting on Partner Authentication Endpoint
LAB
Hard Real World HackerOne #905692
Courier - Missing Rate Limiting on User Registration & Email Enumeration
LAB
Hard Real World HackerOne #658089
WakaTime - Rate Limit Too Lenient on Password Reset Endpoint
LAB
Hard Real World HackerOne #1202408
Redditgifts - Missing Rate Limiting on Adding Comments
LAB
Hard Real World HackerOne #224927
Nextcloud - Missing Rate Limiting on Newsletter Subscription Endpoint
LAB
Hard Real World HackerOne #1166069
UPchieve - Missing Rate Limiting on Contact Us Endpoint
LAB
Hard Real World HackerOne #128777
Algolia - Missing Rate Limiting on Two-Factor Authentication (2FA) Code Verification
LAB
Hard Real World HackerOne #1166066
UPchieve - Missing Rate Limiting on Password Reset Endpoint
LAB
Hard Real World HackerOne #774050
Yelp for Business - Missing Rate Limiting on Resend Confirmation Email Endpoint
LAB
Hard Real World HackerOne #1060541
MTN Group - Missing Rate Limiting on 5-Digit OTP Verification Endpoint

Race Condition

LAB
Easy Training
CodeShack - Race Condition in OTP Resend Limit Bypass
LAB
Hard Real World HackerOne #165570
Slack - Race Condition in Account Creation Survey (Unlimited Credits)
LAB
Hard Real World HackerOne #1285538
Omise - Race Condition in Team Member Invitations
LAB
Hard Real World HackerOne #488985
HackerOne - Race Condition in Claiming Program Credentials
LAB
Hard Real World HackerOne #454949
Hacker101 CTF - Race Condition in Flag Submission
LAB
Hard Real World HackerOne #152717
Urban Dictionary - Race Condition in Definition Votes
LAB
Hard Real World HackerOne #3104355
Dust - Race Condition in Folder Creation (Folder Limit Bypass)

Username/Email Enumeration

LAB
Easy Training
UPchieve - User & Email Enumeration via Password Reset

Parameter Tampering

LAB
Easy Training
Parameter Tampering

SQL Injection

LAB
Easy Training
SQL Injection - Login Bypass
LAB
Easy Training
INSERT SQL Injection - Comment System
LAB
Medium Training
CRUD SQL Injection - Book Management
LAB
Medium Training
Time-based Blind SQL Injection
LAB
Medium Training
Integer-based SQL Injection
LAB
Hard Training
User-Agent Header Blind SQL Injection
LAB
Hard Training
Referer Header Blind SQL Injection
LAB
Hard Training
X-Forwarded-For Header Blind SQL Injection
LAB
Hard Training
Blind SQL Injection via Parameter name - Executive Dashboard
LAB
Hard Training
Blind SQL Injection via PATH_INFO - Industrial Asset Registry
LAB
Hard Training
Blind SQL Injection via Filename - University Course Catalog
LAB
Hard Training
Time-based Blind SQLi via sitemap.xml - ACME Corp Industrial
LAB
Hard Real World HackerOne #403616
Time-based Blind SQLi - Zomato
LAB
Hard Real World HackerOne #297478
Time-based Blind SQLi - GSA Bounty
LAB
Hard Real World HackerOne #1046084
UNION-based SQLi - IntenseDebate
LAB
Hard Real World HackerOne #1069531
Blind SQLi - MTN Group
LAB
Hard Real World HackerOne #273946
ORDER BY SQLi - Grab
LAB
Hard Real World HackerOne #2051931
Boolean-blind SQLi - inDrive
LAB
Hard Real World HackerOne #433792
Time-Based Blind SQLi - Rocket.Chat
LAB
Hard Real World HackerOne #1044716
Boolean-Blind SQLi - Zomato
LAB
Hard Real World HackerOne #923020
UNION-Based SQLi - Acronis
LAB
Hard Real World HackerOne #3198980
UNION SQLi - Automattic
LAB
Hard Real World HackerOne #1224660
Time-Based Blind SQLi - Acronis
LAB
Hard Real World HackerOne #3127198
UNION SQLi - U.S. Dept Of Defense
LAB
Hard Real World HackerOne #838855
Blind SQLi - Zomato
LAB
Medium Real World HackerOne #1042746
Time-Based Blind SQLi - Automattic
LAB
Hard Real World HackerOne #491191
String SQLi - U.S. Dept Of Defense
LAB
Medium Real World HackerOne #2312334
Time-Based Blind SQLi - U.S. Dept Of Defense

Cross-Site Request Forgery

LAB
Easy Training
CSRF Password Change - Unprotected Account Settings
LAB
Easy Training
CSRF Email Hijack - Silent Account Takeover
LAB
Easy Training
CSRF Account Wipe - Irreversible Data Deletion
LAB
Easy Training
CSRF 2FA Bypass - Silent Security Downgrade
LAB
Easy Real World HackerOne #834366
Login CSRF - HackerOne
LAB
Medium Real World HackerOne #339352
Login CSRF - Unikrn
LAB
Hard Real World HackerOne #1122408
CSRF - GitLab
LAB
Medium Real World HackerOne #177508
CSRF - Starbucks
LAB
Hard Real World HackerOne #2712857
CSRF - U.S. Dept of Defense
LAB
Medium Real World HackerOne #1118521
CSRF - U.S. Dept of Defense

Server-Side Template Injection

LAB
Hard Training
CloudGuard - Enterprise Compliance & Security Report Engine Code Execution
LAB
Hard Training
TornadoAlert - Python SRE Incident & Webhook Notification Code Execution
LAB
Hard Training
DocuCraft - Cloud Invoice & Billing Template Engine Code Execution
LAB
Hard Training
PulseMail - Marketing Campaign Template Studio Code Execution
LAB
Easy Training
Template Engine Code Injection
LAB
Medium Real World HackerOne #1104349
SSTI - Glovo
LAB
Medium Real World HackerOne #125980
SSTI - Uber
LAB
Hard Real World HackerOne #164224
SSTI - Unikrn

Server-Side Request Forgery

LAB
Easy Training
Source Code Viewer - Basic cURL SSRF
LAB
Easy Training
Screenshot Tool - URL to Image
LAB
Medium Training
Port-based Timing Attack
LAB
Medium Training
Domain Restriction Bypass with Redirects
LAB
Medium Training
Website Checker with IP Blacklist
LAB
Medium Training
AWS Metadata Filter Bypass
LAB
Easy Training
PDF Generator - URL to PDF

Local File Inclusion

LAB
Easy Training
Path Traversal - Basic
LAB
Medium Training
CMS Local File Inclusion
LAB
Hard Training
File Upload with LFI Vulnerability
LAB
Easy Training
Image Gallery File Inclusion
LAB
Medium Training
Local File Inclusion - Corporate Page Routing
LAB
Medium Training
Local File Inclusion - Documentation Portal Engine
LAB
Medium Training
Local File Inclusion - Multi-Language Blog CMS
LAB
Medium Training
Local File Inclusion - HR Portal File Preview
LAB
Medium Training
Local File Inclusion - Help Desk Attachment Preview
LAB
Medium Training
Local File Inclusion - LMS Course Resource Viewer
LAB
Hard Training
Local File Inclusion - Hospital EMR Medical Report Viewer
LAB
Medium Training
Local File Inclusion - Real Estate CMS Media Loader
LAB
Hard Training
Local File Inclusion - Hosting Panel Log Viewer
LAB
Medium Training
Local File Inclusion - E-Commerce Invoice & Template Renderer
LAB
Hard Training
RecipeBox - Base64-Encoded Path LFI Bypass
LAB
Hard Training
GovDocs - Double URL Encoding LFI Bypass
LAB
Hard Training
Admin Portal - Error Parameter Path Traversal

Remote Code Execution

LAB
Easy Training
OS Command Injection

Insecure Direct Object Reference

LAB
Easy Training
SwiftCart - Insecure Order Invoice Disclosure
LAB
Medium Real World HackerOne #150095
Uber Driver Portal - Trip & Earnings Disclosure
LAB
Easy Training
MediCare+ - Healthcare Records IDOR
LAB
Medium Training
FriendZone - Social Media Profile IDOR
LAB
Medium Training
SecureBank - Banking Portal Account IDOR

Remote File Inclusion

LAB
Easy Training
Remote File Inclusion via URL
LAB
Medium Real World HackerOne #192940
RFI + XSS + SSRF via Unvalidated URL Proxy in GIS Portal (U.S. DoD)
LAB
Medium Training
PageForge CMS - Content Manager Remote & Local File Inclusion
LAB
Medium Training
ShopStream - E-Commerce Bulk Product Import Remote & Local File Inclusion
LAB
Medium Training
StreamFlux - Video Analytics CDN Origin Asset Proxy Remote & Local File Inclusion

XML External Entity

LAB
Easy Training
XML External Entity (XXE) via URL
LAB
Medium Real World HackerOne #248668
XXE on Twitter SMS SXMP API (File Read via operatorId Error Reflection)
LAB
Hard Real World HackerOne #347139
LFI + SSRF via XXE in SVG Emblem Editor (Rockstar Games ImageMagick)
LAB
Hard Real World HackerOne #836877
Blind XXE via JPEG XMP Metadata Injection (Informatica OOB Exfiltration)
LAB
Medium Real World HackerOne #500515
XXE via XML Resume Upload Starbucks China Career Portal (IIS + ASP.NET)
LAB
Medium Training
XXE via XML Registration API - SecureVault Password Manager
LAB
Medium Training
XXE via XML Login API - SecureVault Password Manager

Subdomain Takeovers

LAB
Easy Training
Subdomain Takeovers

Business Logic Vulnerabilities

LAB
Easy Training
Business Logic Vulnerability

Information Disclosure

LAB
Easy Training
Information Disclosure

File Upload Vulnerabilities

LAB
Easy Training
File Upload Vulnerabilities

Special Vulnerabilities

LAB
Easy Training
PHP User Authentication & Secure Registration System
LAB
Medium Training
BookStore - Online Bookstore & Shopping Cart Platform
LAB
Easy Training
Burger Palace - Fast Food Restaurant Portal
LAB
Medium Training
Club Manager - Membership & Events Management Portal
LAB
Medium Training
CoWork Space - Shared Office & Meeting Room Booking System
LAB
Easy Training
Employee Management CRUD System
LAB
Medium Training
DocVault - Enterprise Document Management System
LAB
Easy Training
Restaurant El Paso - Dining & Table Reservations Portal
LAB
Easy Training
English Learning & Vocabulary Portal
LAB
Medium Training
Enigma - College Symposium & Event Management Platform
LAB
Medium Training
Food Order CMS & Restaurant System
LAB
Medium Training
Food Ordering & POS Restaurant Management System
LAB
Medium Training
FoodDelivery - Online Food Ordering & Cart Platform
LAB
Medium Training
Foodie - Gourmet Burger Bar & Table Reservation Platform
LAB
Medium Training
Buffet Box - Digital QR Menu & Cloud Kitchen POS
LAB
Easy Training
GiftStore - Online Gifts & Souvenirs Portal
LAB
Medium Training
Grecko - Mediterranean Bar & Seafood Restaurant
LAB
Easy Training
Grilli - Fine Dining Restaurant & Chef Specials
LAB
Hard Training
Hospital Management System (HMS) - Multi-Portal Healthcare
LAB
Medium Training
Internship & Student Placement Management System
LAB
Medium Training
Johnny's Dining & Bar - Restaurant POS & Management
LAB
Medium Training
Krables - Multi-Vendor E-Commerce Platform
LAB
Medium Training
Management Lab - Resource & Laboratory Booking Portal
LAB
Easy Training
Picture Perfect - Real Estate & Property Showcase
LAB
Hard Training
Planet - CSP Protected Content Security Bypass
LAB
Easy Training
RainyRoof - Roofing Services & Quotation Portal
LAB
Medium Training
Rate Limiting & Brute Force Protection Defense Lab
LAB
Hard Training
ReadSphere - Book Review & Community Library Platform
LAB
Medium Training
Vincent Pizza - Authentic Italian Restaurant & Ordering
LAB
Hard Training
Space - Content Security Policy (CSP) Bypass Lab
LAB
Medium Training
EduPro - Student & Academic Management System
LAB
Medium Training
ET LAB - Student & College Administration Portal
LAB
Easy Training
Tour & Travel Vacation Booking Portal
LAB
Medium Training
TripTrip - Tour Agency & Travel Booking Portal
LAB
Medium Training
University Academic & Admissions Portal
LAB
Medium Training
WebFilesDesk - Self-Hosted File Explorer & Manager
LAB
Medium Training
Yummy - Food Delivery & Restaurant Platform
LAB
Hard Training
ControlHub - JSON Response Manipulation Auth Bypass
LAB
Hard Training
VaultTech - JWT Token Credential Reuse Across Admin Panels
LAB
Hard Training
CloudSync - PII Leaked on Unauthorized File
LAB
Hard Training
CBSE - Default Credentials Authentication Bypass
LAB
Hard Training
CDN Directory Listing - PII Exposed
LAB
Hard Training
Aliyun WAF Bypass - Bypass WAF Rules
LAB
Hard Training
Aliyun WAF Bypass - Bypass WAF Rules
LAB
Hard Training
Aliyun WAF Bypass
LAB
Hard Training HackerOne #1164452
Unrestricted File Upload - PHP Profile Picture Leads to Remote Code Execution