The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

9.6K stars 1.6K forks 9.6K watchers Creative Commons Attribution Share Alike 4.0 International
application-security appsec best-practices bugbounty guide hacking hacktoberfest owasp penetration-testing pentesting security
42 Open Issues Need Help Last updated: Jul 26, 2026

Open Issues Need Help

View All on GitHub

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
Missing closing bracket about 2 months ago
help wanted revise

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
Study of API Testing about 2 months ago
enhancement help wanted

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
Dream 2 months ago
help wanted new

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
help wanted new good first issue

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
enhancement help wanted new good first issue

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

AI Summary: The issue proposes adding a new section to the documentation, specifically under '4.12 API Testing,' to guide users on how to check for sensitive information in API responses. This is crucial because developers sometimes inadvertently expose data like passwords or API keys by serializing entire objects directly into API output. The goal is to prevent security vulnerabilities arising from such exposures.

Complexity: 3/5
help wanted new

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
help wanted revise

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
revise good first issue

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
enhancement help wanted

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
new good first issue

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
enhancement help wanted revise

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
enhancement help wanted new

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
enhancement help wanted

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

AI Summary: This GitHub issue discusses the various browser storage methods (e.g., LocalStorage, SessionStorage, IndexedDB) and their security implications, building on previous discussions and CLNT-12. The core question is whether the OWASP WSTG should provide detailed guidance on these techniques and their security aspects, and if so, how best to integrate this information into the guide.

Complexity: 4/5
help wanted

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
help wanted revise

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
help wanted question revise

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
enhancement help wanted

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

AI Summary: This GitHub issue proposes adding a complete Hindi translation for the Web Security Testing Guide (WSTG) to make this critical resource accessible to over 600 million Hindi speakers globally, particularly India's large developer and cybersecurity community. The proposal outlines creating a new branch, translating all chapters, adding a Hindi glossary, and a maintenance plan, highlighting the current absence of any Indian language translations.

Complexity: 5/5
help wanted new

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

AI Summary: This GitHub issue identifies a minor terminology error in the "Fingerprint Web Server > Sending Malformed Requests" documentation. It incorrectly labels the "HTTP version" part of an HTTP request line (e.g., `HTTP/1.1`) as the "method." The proposed solutions are to either modify the example to clarify the method or correct the text to accurately refer to it as the "HTTP version."

Complexity: 1/5
help wanted revise

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
help wanted revise

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
enhancement help wanted new good first issue

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

AI Summary: The issue proposes enhancing the OWASP Web Security Testing Guide (WSTG) by integrating references to practical labs from OWASP SKF (Security Knowledge Framework). The goal is to link specific SKF lab write-ups, which demonstrate "how to test" for various vulnerabilities, directly within the relevant sections of the WSTG. This would provide WSTG users with hands-on examples and practical exercises to complement the testing methodologies described.

Complexity: 3/5
good first issue integration

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
Broken link for 9 months ago
bug help wanted good first issue

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security
new revise good first issue

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

AI Summary: This GitHub issue points out a misclassification in the WSTG guide, where "Direct Page Request (Forced Browsing)" is currently listed under "Testing for Bypassing Authentication Schema." The author argues that forced browsing isn't always an authentication bypass, as it could simply be accessing an unauthenticated page, which is more akin to information disclosure or access control. The suggestion is to clarify or reclassify this section to improve structural consistency and conceptual accuracy.

Complexity: 2/5
help wanted revise

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security

AI Summary: Expand the OWASP Web Security Testing Guide's section on testing payment functionality by adding new test cases focusing on real-world business logic flaws such as race conditions, multi-step confirmation vulnerabilities, cart manipulation, and improper source/destination validation in transfers. This involves researching common payment system vulnerabilities, crafting detailed test cases, and contributing the changes via a pull request to the OWASP WSTG GitHub repository.

Complexity: 4/5
help wanted new

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

#application-security#appsec#best-practices#bugbounty#guide#hacking#hacktoberfest#owasp#penetration-testing#pentesting#security