OWASP Broken Web Applications Project
Clone or download
Latest commit 2020de0 Mar 7, 2016


Open Web Application Security Project (OWASP) Broken Web Applications Project, a collection of vulnerable web applications that is distributed on a Virtual Machine in VMware format compatible with their no-cost VMware Player and VMware vSphere Hypervisor (ESXi) products (along with their older and commercial products).

Led by Chuck Willis (chuck (at) securityfoundry (dot) com) and sponsored by Mandiant, a FireEye Company.

Version 1.2 of the VM was released on August 3, 2015. Download from http://sourceforge.net/projects/owaspbwa/files/.

For more information on the project, see the Project User Guide. To contribute, report bugs, or see / add to the list of known vulnerabilities in the project application, see Getting Involved.

Note - This project is a collection of open source software from various sources, along with some custom modifications and pieces to make it all work together. The license for each component may vary. The GPLv2 license listed on the left for this project is only for any custom modifications and code created for this project.