Deliberately vulnerable web targets for the Certified Web App Pentester (CxWAP) track. Authorized practice only.
LearnEvery CxWAP WEB syllabus bug class as its own focused lab: CSRF, JWT, IDOR, BAC, XSS (reflected/stored/DOM/mXSS), SSTI, CSTI, business logic, HPP, LFI, clickjacking and more.
Exam simOne realistic SaaS app that hides all 15 bug classes in believable features. Hunt it like the real exam; capture every class to unlock the final flag.