OWASP Juice Shop – a realistic vulnerable web app for security training
Juice Shop is a fully functional web application intentionally riddled with security flaws from the OWASP Top Ten and beyond. It lets learners, trainers, and security tools practice finding and exploiting vulnerabilities in a safe, controlled environment. The app runs locally or via Docker, offering a rich UI and API for realistic attack scenarios. Its comprehensive coverage and polished implementation make it a go‑to platform for security education and tool benchmarking.
View on GitHub →ctf-in-a-box-test/juice-shop