0xBOverchunked
CTF

0xBOverchunked

Boolean-based SQL injection. Transfer-Encoding chunked
AbuseHumanDB
CTF

AbuseHumanDB

Cross-Site Search. Bypass Same-Origin Policy for exfiltration
Almost SSTI
CTF

Almost SSTI

ImaginaryCTF 13/07/2022. 50 points. Server-Side Template Injection. Flask console
Amidst Us
CTF

Amidst Us

Python. Third-party dependencies. Code Injection. RCE
baby auth
CTF

baby auth

Session cookies. Authentication bypass
baby BoneChewerCon
CTF

baby BoneChewerCon

PHP. Laravel Debugger
baby breaking grad
CTF

baby breaking grad

JavaScript. Prototype Pollution
baby CachedView
CTF

baby CachedView

SSRF using iframe
baby interdimensional internet
CTF

baby interdimensional internet

Code injection. Read remote file
baby nginxatsu
CTF

baby nginxatsu

nginx. Directory listing
baby ninja jinja
CTF

baby ninja jinja

SSTI with limited characters
baby todo or not todo
CTF

baby todo or not todo

Broken Access Control
baby WAFfles order
CTF

baby WAFfles order

XML External Entity injection
baby website rick
CTF

baby website rick

Insecure deserialization with pickle
Bad JWT
CTF

Bad JWT

SECCON CTF Quals 2023. Node.js. JWT. Prototype Pollution
BatchCraft Potions
CTF

BatchCraft Potions

GraphQL batching attack. OTP and rate limit bypass. JWT. CSP. DOM Clobbering. XSS
BatchCraft Potions
CTF

BatchCraft Potions

HTB UniCTF 2022. GraphQL batching attack. OTP and rate limit bypass. JWT. CSP. DOM Clobbering. XSS
BlinkerFluids
CTF

BlinkerFluids

Node.js. Third-party dependencies. Code Injection. RCE
Breaking Bank
CTF

Breaking Bank

Open Redirect. JWKS and JWT forgery. OTP bypass
Breaking Bank
CTF

Breaking Bank

HTB UniCTF 2024. Open Redirect. JWKS and JWT forgery. OTP bypass
CandyVault
CTF

CandyVault

MongoDB. NoSQL injection
Cookies
CTF

Cookies

picoCTF 2021. 40 points. Modify cookies
CurlAsAService
CTF

CurlAsAService

Parameter injection. Local File Read
Cursed Secret Party
CTF

Cursed Secret Party

XSS. CSP bypass
Cursed Secret Party
CTF

Cursed Secret Party

XSS. CSP bypass
Didactic Octo Paddles
CTF

Didactic Octo Paddles

JWT. Server-Side Template Injection
Didactic Octo Paddles
CTF

Didactic Octo Paddles

HTB CA 2023. JWT. Server-Side Template Injection
Don't Bump Your Head(er)
CTF

Don't Bump Your Head(er)

HTTP request headers
E.Tree
CTF

E.Tree

XPATH injection. Automate flag extraction
emoji voting
CTF

emoji voting

Boolean-based SQLi in ORDER. Automate flag extraction
Evaluation Deck
CTF

Evaluation Deck

Python. Code injection
ExpressionalRebel
CTF

ExpressionalRebel

Server-Side Request Forgery. Regular Expression Denial of Service
Fasting
CTF

Fasting

ImaginaryCTF 28/09/2022. 50 points. API docs
Flag Command
CTF

Flag Command

API. Developer tools
Full Stack Conf
CTF

Full Stack Conf

Cross-Site Scripting
funnylogin
CTF

funnylogin

DiceCTF 2024 Quals. SQLi. JavaScript object attributes
GET aHEAD
CTF

GET aHEAD

picoCTF 2021. 20 points. HEAD request method
GhostlyTemplates
CTF

GhostlyTemplates

Go. Server-Side Template Injection. Local File Read
Gobustme 👻
CTF

Gobustme 👻

Fuzzing routes
Guglu v2
CTF

Guglu v2

HackOn CTF 2024. Data exfiltration by oracle
Gunship
CTF

Gunship

Prototype Pollution. AST Injection
HauntMart
CTF

HauntMart

Server-Side Request Forgery. IP address bypass
Horror Feeds
CTF

Horror Feeds

Stack-based SQL injection
Horror Feeds
CTF

Horror Feeds

Stack-based SQL injection
HTBank
CTF

HTBank

HTTP Parameter Pollution
Insp3ct0r
CTF

Insp3ct0r

picoCTF 2019. 50 points. HTML, CSS and JS
Intergalactic Post
CTF

Intergalactic Post

SQLi in SQLite to RCE in PHP
jscalc
CTF

jscalc

JavaScript. Code injection
Juggling facts
CTF

Juggling facts

PHP. Type Juggling
Juggling Facts
CTF

Juggling Facts

PHP. Type Juggling
KORP Terminal
CTF

KORP Terminal

SQL injection. Password hash cracking
Kryptos Support
CTF

Kryptos Support

Cross-Site Scripting. Insecure Direct Object Reference
Lazy Ballot
CTF

Lazy Ballot

CouchDB. NoSQL injection. Authentication bypass
Letter Dispair
CTF

Letter Dispair

PHP. Remote Code Execution. PHPMailer (CVE)
Login Please
CTF

Login Please

ImaginaryCTF 12/09/2022. 75 points. MD5 hash. Prototype Pollution
looking glass
CTF

looking glass

Command injection. Remote Code Execution
LoveTok
CTF

LoveTok

PHP. Code injection. Remote Code Execution
Micro-CMS v1
CTF

Micro-CMS v1

Basic web pentesting. XSS, IDOR, SQLi
Model E1337 - Rolling Code Lock
CTF

Model E1337 - Rolling Code Lock

Advanced web pentesting and cryptanalysis. XXE. Reverse Engineering
Mutation Lab
CTF

Mutation Lab

SVG file read through image. Forge session cookie
Neonify
CTF

Neonify

CRLF Injection. RegEx bypass. Server-Side Template Injection
One Time Pages
CTF

One Time Pages

HackOn CTF 2025. XSS. Service Worker. Tabnabbing
OnlyHacks
CTF

OnlyHacks

Cross-Site Scripting. Cookie hijacking
Orbital
CTF

Orbital

SQL injection. Directory Traversal. Local File Read
Orbital
CTF

Orbital

HTB CA 2023. SQL injection. Directory Traversal. Local File Read
Passman
CTF

Passman

GraphQL. IDOR
Passman
CTF

Passman

HTB CA 2023. GraphQL. IDOR
Percetron
CTF

Percetron

HA-Proxy. HTTP request smuggling via WebSocket. Server-Side Request Forgery. MongoDB Wire Protocol. Gopher Protocol. Cypher injection (neo4j). Command injection. RCE
Percetron
CTF

Percetron

HTB CA 2024. HA-Proxy. HTTP request smuggling. Server-Side Request Forgery. MongoDB Wire Protocol. Gopher Protocol. Cypher injection (neo4j). Command injection. RCE
POST Practice
CTF

POST Practice

HTTP POST request
ProxyAsAService
CTF

ProxyAsAService

Server-Side Request Forgery. localhost bypass. HTTP Request URI
Public Pages
CTF

Public Pages

HackOn CTF 2025. SvelteKit. Development mode. SQL wildcard injection
PumpkinSpice
CTF

PumpkinSpice

Cross-Site Request Forgery. Remote Code Execution
Red Island
CTF

Red Island

SSRF. Path Traversal. Gopher protocol. Redis RCE
Robotic
CTF

Robotic

ImaginaryCTF 04/11/2022. 50 points. robots.txt
sanitize
CTF

sanitize

SQL injection. Authentication bypass
Saturn
CTF

Saturn

Server-Side Request Forgery. TOCTOU
Secure
CTF

Secure

ImaginaryCTF 08/11/2022. 50 points. HTTPs certificate
Situated
CTF

Situated

ImaginaryCTF 03/11/2022. 50 points. Inspect HTML code
Slippy
CTF

Slippy

TAR Directory Path Traversal. Server-Side Template Injection
Spellbound Servants
CTF

Spellbound Servants

Insecure deserialization with pickle
Spiky Tamagotchi
CTF

Spiky Tamagotchi

Authentication bypass. JavaScript code injection
Spookifier
CTF

Spookifier

Server-Side Template Injection
Spookifier
CTF

Spookifier

Server-Side Template Injection
SpookTastic
CTF

SpookTastic

Cross-Site Scripting
Spybug
CTF

Spybug

Malicious file upload. SSTI to XSS. CSP bypass
SpyBug
CTF

SpyBug

HTB CA 2023. Malicious file upload. SSTI to XSS. CSP bypass
Templated
CTF

Templated

Flask. Server-Side Template Injection. RCE
Testimonial
CTF

Testimonial

Go. gRPC. Client-side verification. Directory traversal. Arbitrary File Write. Server-Side Rendering
Testimonial
CTF

Testimonial

HTB CA 2024. Go. gRPC. Client-side verification. Directory traversal. Arbitrary File Write. Server-Side Rendering
The Magic Informer
CTF

The Magic Informer

Directory Traversal. Local File Read. JWT. Broken Access Control. SSRF. Command Injection. RCE
The Magic Informer
CTF

The Magic Informer

HTB UniCTF 2022. Directory Traversal. Local File Read. JWT. Broken Access Control. SSRF. Command Injection. RCE
TimeKORP
CTF

TimeKORP

Command injection
Toxic
CTF

Toxic

PHP deserialization. Local File Inclusion. Log Poisoning
Trapped Source
CTF

Trapped Source

HTML code inspection
TrapTrack
CTF

TrapTrack

Insecure Deserialization in pickle. SSRF in Redis
TrapTrack
CTF

TrapTrack

HTB CA 2023. Insecure Deserialization in pickle. SSRF in Redis
Userland City
CTF

Userland City

PHP. Laravel exploit
wafwaf
CTF

wafwaf

PHP. Time-based SQL injection. WAF bypass
Watersnake
CTF

Watersnake

Java. CVE. SnakeYAML insecure deserialization
where are the robots
CTF

where are the robots

picoCTF 2019. 100 points. robots.txt
Wild Goose Hunt
CTF

Wild Goose Hunt

MongoDB. NoSQL injection. Automate flag extraction