Skip to content
#

owasp-api-security-top-10

Here are 2 public repositories matching this topic...

A modern, deliberately-vulnerable, API-first web app - a DVWA alternative covering the OWASP API Security Top 10 (2023) and Web Top 10 (2021). Two distinct origins (Next.js 14 + FastAPI) with a cookie-to-Bearer JWT bridge and 45+ catalogued vulns, each paired with a secured twin. Local, educational use only.

  • Updated Jul 27, 2026
  • TypeScript

Improve this page

Add a description, image, and links to the owasp-api-security-top-10 topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the owasp-api-security-top-10 topic, visit your repo's landing page and select "manage topics."

Learn more