vulnlab.dev contains real, exploitable bugs by design. Point your tools here and see what they catch.
A reference target for security tools
Each vulnerability class lives on its own subdomain. Every lab links to its own source. Bring a SAST scanner, a DAST scanner, an LLM, or all three — see what each one finds.
xss.vulnlab.devsqli.vulnlab.devssti.vulnlab.devCarl Sampson (chs) — application security researcher. vulnlab.dev is a side project alongside other things I run:
Found a bug in the lab platform itself (not in the intentionally-vulnerable apps)? Email carl.sampson@gmail.com.