Deliberately vulnerable web targets for the Certified Web App Pentester (CxWAP) track. Authorized practice only.
Three steps: learn a module → drill the technique → prove it on an exam sim.
Step 1 · LearnNew to a topic? Start here. Learn each CWAP module in its own realistic lab, in syllabus order, with on-page instructions and goal hints that walk you from zero to hunting.
What the module labs are & the full list → Step 2 · DrillOnce you know a topic, sharpen it. Every module has naked labs (a few features, exactly one exploit — the raw technique in isolation) and methodology labs (realistic apps with decoys where you must hunt and build a repeatable method).
What “naked” vs “methodology” means & the full list → Step 3 · Prove itBig, realistic apps that hide the whole syllabus with no labels and no flags — exactly like the real 24-hour CWAP exam. Prove you can find and chain it all.
What an exam sim is & how to tackle the exam → Engagements · TimedTimed, no-flag pentest engagements. Pass a 50-question quiz, write a plan in 90 minutes, then get 24 hours to compromise a full application — then record your own ≤10-min debrief video. The closest thing to the real job.
How engagements work & the CWAP path → Reference · WatchEvery CWAP attack, animated step by step — recon, IDOR/BOLA, XSS, CSRF, SSRF, JWT, secrets, logic flaws and full chains. Short visual walkthroughs of exactly how each exploit works. Great before or after a lab.
Browse all animations →More hands-on reps: HackXpert Labs ↗