Skip to content

Topic

Deliberately vulnerable applications

Intentionally insecure software built for security training and capture-the-flag practice, meant to be run only in isolated environments.

Current clusters

build1 publisher

An <object> tag turns an uploaded SVG into stored XSS for every visitor

OopsSec Store, a deliberately vulnerable Next.js app, lets an admin-uploaded SVG run JavaScript in every visitor's browser. It works because the server trusts the client-set Content-Type and the product page renders SVGs through an <object> tag.

Publishers:dev.to

Reality

Evidence62
Adoption
Insufficient
Hype gap+8
Incentives40
Confidence72