Skip to content

Repository files navigation

🎯 VT Templates

A curated collection of vulnerable targets for security testing, training, and research.

Generate Templates


🎯 Targets

Type ID Name Tech Tags
🔴 vt-2026-57827 RSFiles! for Joomla - Unauthenticated Arbitrary File Upload to RCE (CVE-2026-57827) rsjoomla-rsfiles, joomla cve-2026 cve-2026-57827
🔴 vt-2026-3854 GitHub Enterprise Server - X-Stat Field Injection to Pre-Receive Hook RCE github-enterprise-server rce github
🔴 vt-2026-54433 Roundcube Webmail - Zero-Click Stored XSS in Plain-Text Rendering roundcube-webmail xss zero-click
🔴 vt-2026-56139 Apache Camel camel-undertow - Rest DSL muteException Stack Trace Disclosure apache-camel, camel-undertow info-disclosure stack-trace
🔴 vt-2026-63030 WordPress Core - REST Batch Route Confusion to SQLi (wp2shell) wordpress sqli rce
🔴 vt-2026-1492 WordPress User Registration & Membership - Unauthenticated Privilege Escalation wordpress privilege-escalation unauthenticated
🔴 vt-2026-27971 Qwik - Unauthenticated RCE via server$ Deserialization qwik rce deserialization
🔴 vt-2025-32778 Web-Check - Command Injection via Screenshot API web-check rce command-injection
🔴 vt-2026-27944 Nginx UI - Unauthenticated Backup Download with Encryption Key Disclosure nginx-ui nginx-ui backup
📊 vt-dagu Dagu Workflow Engine - Unauthenticated Remote Code Execution dagu, dagu-workflow-engine dagu rce
🔴 vt-2025-71243 SPIP Saisies Plugin - Unauthenticated Remote Code Execution spip, saisies, php spip saisies
📊 vt-vlife Vlife FastJSON Deserialization to RCE (GHSL-2024-300) vlife deserialization fastjson
🔴 vt-2023-3452 WordPress Canto Plugin Unauthenticated Remote File Inclusion (CVE-2023-3452) wordpress, canto rfi rce
🔴 vt-2026-1357 WPvivid Backup & Migration - Unauthenticated Arbitrary File Upload to RCE wordpress, wpvivid-backuprestore, php wordpress wpvivid
🔴 vt-2026-21962 Oracle WebLogic Server Proxy Plug-in - Authentication Bypass oracle-weblogic, oracle-http-server, weblogic-proxy-plugin oracle weblogic
🔴 vt-2025-24963 Vitest Browser Mode API Exposure (LFI & RCE) (CVE-2025-24963) vitest lfi rce
🔴 vt-2026-25512 Group-Office - Remote Code Execution (OS Command Injection) group-office, php groupoffice php
🔴 vt-2026-23829 mailpit - Mailpit has an SMTP Header Injection via Regex Bypass mailpit, web, SMTP go medium
🔴 vt-2026-1207 Django SQL Injection in RasterField lookup (CVE-2026-1207) django sqli django
🔴 vt-2025-64459 Django - CVE-2025-64459 django, python, mysql injection sqli-like
🔴 vt-2025-55182 React Server Components - Remote Code Execution react-server-components, nextjs rce deserialization
🔴 vt-2025-29927 Next.js Middleware Bypass web-application nextjs middleware
🔴 vt-2024-53995 SickChill Login - Open Redirect python, media server open-redirect redirect
🧪 vt-webgoat WebGoat java owasp web
🧪 vt-mutillidae-ii OWASP Mutillidae II php, mysql owasp web
🧪 vt-juice-shop OWASP Juice Shop nodejs, angular, express, sqlite xss injection
🧪 vt-dvwa Damn Vulnerable Web App (DVWA) mysql, php dvwa php
🧪 vt-bwapp bWAPP php, mysql owasp web
📊 vt-xbow-104 Loan Calculator - Simple web ssti default_credentials
📊 vt-xbow-103 Trusty Cookie web information_disclosure idor
📊 vt-xbow-102 Email updates web default_credentials business_logic
📊 ... 101 more benchmarks

Currently tracking 132 security targets, including 21 CVEs, 5 labs, and 104 benchmarks.

About

No description, website, or topics provided.

Resources

Code of conduct

Contributing

Security policy

Stars

7 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages