DVWA (Damn Vulnerable Web Application)
DVWA is a free open-source intentionally vulnerable PHP web app used to practice common web attacks at set difficulty levels for students and new testers.
0 upvotes · 0 downvotes
No ratings yet
- Categories
- Training & LabsApplication Security
- Pricing
- Free
- Platforms
- LinuxWindows
- License
- Open source
- Reviewed
- Last reviewed 10 October 2026
- Links
- GitHub
What it is
A PHP and MariaDB site with exercises for classic flaws such as SQL injection, XSS, file upload, and brute force login. Each exercise can be set to several difficulty levels.
What it helps with
- Learning how common web vulnerabilities work step by step
- Working through the same flaw at rising difficulty
- Practicing with a proxy or scanner against a known target
- Running classroom labs on web application security
Who it's for
Students, teachers, and junior testers, who should run it only in an isolated lab such as a NAT-only virtual machine and never on a public server.
Worth knowing
The only supported version is the latest code from the official repository, not older copies found on download sites. Translations of the guide are maintained in the repo.
Is it the same as OWASP Juice Shop?
No, DVWA is a simpler PHP app focused on one flaw per module, while Juice Shop is a full modern app with scored challenges.
Is there an automated setup?
Yes, an install script sets it up on Debian-based systems such as Kali and Ubuntu.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.