DVWS-Node

DVWS-Node

Vulnerable applications used to learn and test Web service/API-related vulnerabilities

510GitHub
Description

"Damn Vulnerable Web Services Node" (DVWS-Node) is a vulnerable application designed to learn and test Web services/API-related vulnerabilities. The application is designed to help security researchers, developers, and learners understand and practice security vulnerabilities in various Web services and APIs. DVWS contains the following common API/Web service vulnerabilities: - Unsafe direct object references - Horizontal access control issues - Vertical access control issues - A large number of assignment vulnerabilities - Cross-site scripting attack (XSS) - NoSQL injection - Server-side request counterfeiting (SSRF) - JSON Web Token (JWT) key brute force cracking - information leakage - Hidden API features exposed - Cross-domain resource sharing (CORS) configuration error - JSON Hijacking - SQL injection - XML External Entity Injection (XXE) - command injection - XPath injection - XML-RPC user enumeration - Open redirection - path traversal - Unsafe deserialization - Sensitive data exposure - GraphQL access control issues - Enable GraphQL introspection - GraphQL arbitrary file writing - GraphQL batch brute force cracking - Client template injection Register directly and use it.

Screenshots
Screenshot 1
Mobile Screenshots
Mobile Screenshot 1
App Information
Version
0.1.1
Updated
October 11, 2025
Source Code
snoopysecurity
Platform Support
PCMobile
Keywords
safe shooting range
DVWS-Node | SelfHost