Local only This shop is broken on purpose for scanner practice. Keep it on 127.0.0.1 — don't put it online.
Vulnshop. second-hand merch, first-hand mistakes

Quest board

10 flags · zero mercy

Every flag is hidden behind a real vulnerability — no free reads. Exploit the app, recover the VULNSHOP{...} token, and submit it here. First player to all 10 takes the shelf.

Submit with curl: curl -X POST http://127.0.0.1:5000/api/submit-flag -H "Content-Type: application/json" -d '{"player":"your-name","flag":"VULNSHOP{...}"}'

See the standings: /leaderboard · JSON: /api/leaderboard

SQL Injection

1. Secret Stash

There is a table nobody lists on the shop floor.

Path Traversal

2. Off the Shelf

The download shelf keeps stock out of reach of the rack.

Exposed Backup

3. The Forgotten Zip

Someone archived a flag and left it on the web root.

Secret Exposure

4. Left Lying Around

Config files should never ship with the app.

JWT / Auth Bypass

5. Forged Badge

The back office badge can be forged if the algorithm is not checked.

XXE

6. Entity Digestion

An XML parser that resolves external entities can read files.

IDOR

7. Someone Else's Receipt

One receipt has a secret note. Try ids nobody told you about.

Weak Crypto

8. Four Little Numbers

Password resets use a 4-digit token derived from the email.

Information Disclosure

9. Open Book

The debug endpoint spills everything, including one quest.

Remote Code Execution

10. Full Send

If you can run code, read the flag file in /app/files.

Submit a flag