WARNING: Intentionally vulnerable application for testing Burp Bounty profiles. DO NOT expose to the internet.
XSS (14 profiles)
SQL Injection (7 profiles)
Remote Code Execution (13 profiles)
Path Traversal (2 profiles + CVEs)
SSRF (6 profiles)
Open Redirect (3 profiles)
CORS Misconfiguration (1 profile)
CRLF Injection (1 profile)
SSTI (1 profile)
XXE (3 profiles)
GraphQL (6 profiles)
CVEs (42 profiles)
WordPress (10 profiles)
Spring Boot (2 profiles)
Drupal (2 profiles)
DWR (1 profile)
Misc Discovery
Passive Detection Triggers
Header Injection (Collaborator)