Intentionally Vulnerable Website
1. Reflected XSS
Submit
You entered:
2. Missing CSRF Protection
Username:
Change Username
3. Sensitive Information
4. Missing Security Headers
No CSP, HSTS, X-Frame-Options, etc.
5. Cookie without Secure/HttpOnly
6. Insecure Form
Username:
Password:
Login