WEB SECURITY ACADEMY

All Labs

Hands-on, interactive labs to practice exploiting real-world web vulnerabilities. From SQL injection to prototype pollution — master them all.

0 Total Labs
0 Apprentice
0 Practitioner
0 Expert

Mystery Lab Challenge

Try solving a random lab with the title and description hidden. Great for practicing recon and analysis.

Take the challenge →

SQL injection

0 labs

Labs coming soon for this topic

Cross-site scripting (XSS)

0 labs

Labs coming soon for this topic

Cross-site request forgery (CSRF)

0 labs

Labs coming soon for this topic

Clickjacking

0 labs

Labs coming soon for this topic

DOM-based vulnerabilities

0 labs

Labs coming soon for this topic

Cross-origin resource sharing (CORS)

0 labs

Labs coming soon for this topic

XML external entity (XXE) injection

0 labs

Labs coming soon for this topic

Server-side request forgery (SSRF)

0 labs

Labs coming soon for this topic

HTTP request smuggling

0 labs

Labs coming soon for this topic

OS command injection

0 labs

Labs coming soon for this topic

Server-side template injection

0 labs

Labs coming soon for this topic

Path traversal

0 labs

Labs coming soon for this topic

Access control vulnerabilities

0 labs

Labs coming soon for this topic

Authentication

0 labs

Labs coming soon for this topic

WebSockets

0 labs

Labs coming soon for this topic

Web cache poisoning

0 labs

Labs coming soon for this topic

Insecure deserialization

0 labs

Labs coming soon for this topic

Information disclosure

0 labs

Labs coming soon for this topic

Business logic vulnerabilities

0 labs

Labs coming soon for this topic

HTTP Host header attacks

0 labs

Labs coming soon for this topic

OAuth authentication

0 labs

Labs coming soon for this topic

File upload vulnerabilities

0 labs

Labs coming soon for this topic

JWT

0 labs

Labs coming soon for this topic

Essential skills

0 labs

Labs coming soon for this topic

Prototype pollution

0 labs

Labs coming soon for this topic

GraphQL API vulnerabilities

0 labs

Labs coming soon for this topic

Race conditions

0 labs

Labs coming soon for this topic

NoSQL injection

0 labs

Labs coming soon for this topic

API testing

0 labs

Labs coming soon for this topic

Web LLM attacks

0 labs

Labs coming soon for this topic

Web cache deception

0 labs

Labs coming soon for this topic