Web Application Security Path

A structured, 30-part roadmap covering web application security from the fundamentals through the broader OWASP-aligned vulnerability landscape — work through it in order, or jump to whatever topic you need.

  1. 1 SQL Injection
  2. 2 Cross-Site Scripting (XSS)
  3. 3 Authentication Vulnerabilities
  4. 4 Authorization & Access Control
  5. 5 IDOR / BOLA
  6. 6 CSRF (Cross-Site Request Forgery)
  7. 7 Session Management Vulnerabilities
  8. 8 File Upload Vulnerabilities
  9. 9 Path Traversal
  10. 10 Command Injection
  11. 11 Server-Side Request Forgery (SSRF)
  12. 12 XXE Injection
  13. 13 Server-Side Template Injection (SSTI)
  14. 14 LDAP Injection
  15. 15 NoSQL Injection
  16. 16 XML Injection
  17. 17 HTTP Request Smuggling
  18. 18 HTTP Parameter Pollution
  19. 19 Open Redirect
  20. 20 Clickjacking
  21. 21 Security Misconfiguration
  22. 22 Sensitive Data Exposure
  23. 23 Information Disclosure
  24. 24 Cryptographic Failures
  25. 25 Business Logic Vulnerabilities
  26. 26 Race Conditions
  27. 27 Prototype Pollution
  28. 28 Web Cache Poisoning
  29. 29 Web Cache Deception
  30. 30 CORS Misconfiguration

Want to browse by category instead? Head to Learning Domains.