26/05/23, 11:55 OWASP WebGoat | OWASP Foundation Please support the OWASP mission to improve software security through open source initiatives and community education. Donate Now! Donate Store PROJECTS CHAPTERS EVENTS ABOUT Join Search OWAS OWASP WebGoat Main Goals Lessons Start WebWolf Getting started 1. Run using Docker The easiest way to start WebGoat as a Docker container is to use the all-in-one Docker container. This is a Docker image that has WebGoat and WebWolf running inside. docker run -p 8080:8080 -p 9090:9090 -p 80:8888 -e TZ=Europe/Amsterdam webgoat/goatandwolf:latest and browse to http://localhost:8080/WebGoat. 2. Standalone Download the latest WebGoat and WebWolf release from https://github.com/WebGoat/WebGoat/releases Store Donate Watch 24 Join 64 Star The OWASP® Foundation works to improve the security of software through its community-led open source software projects, hundreds of chapters worldwide, tens of thousands of members, and by hosting local and global conferences. Downloads Standalone jars Docker Image Code Repository Source code Helping the Goat! java -jar webgoat-server-8.1.0.jar [-server.port=8080] [--server.address=localhost] java -jar webwolf-8.1.0.jar [-server.port=9090] [--server.address=localhost] Report an issue Contributing to WebGoat Forking WebGoat in GitHub Solutions and browse to http://localhost:8080/WebGoat This website uses cookies to analyze our traffic and only Gitter The latest version of WebGoat needs Java 15 or Accept share that information with our analytics partners. Mail above. By default, WebGoat uses port 8080, the https://owasp.org/www-project-webgoat/ x 1/4 26/05/23, 11:55 OWASP WebGoat | OWASP Foundation database uses 9000 and WebWolf use port 9090 StackOverflow with the environment variable WEBGOAT_PORT, WEBWOLF_PORT and WEBGOAT_HSQLPORT you can set Twitter Slack different values. export WEBGOAT_PORT=18080 export WEBGOAT_HSQLPORT=19001 export WEBWOLF_PORT=19090 java -jar webgoat-server-8.1.0.jar java -jar webwolf-8.1.0.jar Classification Tool Audience Builder Breaker Defender Use set instead of export on Windows cmd. Leaders Bruce Mayhew Nanne Baars Jason White René Zubčević Upcoming OWASP Global Events OWASP Global AppSec Singapore 2023 October 4-5, 2023 OWASP Global AppSec Washington DC 2023 October 30 November 3, 2023 OWASP Global AppSec San Francisco 2024 September 23-27, 2024 OWASP Global AppSec Washington DC 2025 This website uses cookies to analyze our traffic and only share that information with our analytics partners. https://owasp.org/www-project-webgoat/ November 3-7, 2025 x Accept 2/4 26/05/23, 11:55 OWASP WebGoat | OWASP Foundation OWASP Global AppSec San Francisco 2026 November 2-6, 2026 Edit on GitHub Spotlight: Datadog Datadog is the essential monitoring and security platform for cloud applications. We bring together end-to-end traces, metrics, and logs to make your applications, infrastructure, and third-party services entirely observable. These capabilities help businesses secure their systems, avoid downtime, and ensure customers are getting the best user experience. Corporate Supporters image Become a corporate supporter HOME PROJECTS CHAPTERS EVENTS ABOUT This website uses cookies to analyze our traffic and only PRIVACY SITEMAP with CONTACT share that information our analytics partners. https://owasp.org/www-project-webgoat/ x Accept 3/4 26/05/23, 11:55 OWASP WebGoat | OWASP Foundation OWASP, Open Web Application Security Project, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, LASCON, and the OWASP logo are trademarks of the OWASP Foundation, Inc. Unless otherwise specified, all content on the site is Creative Commons Attribution-ShareAlike v4.0 and provided without warranty of service or accuracy. For more information, please refer to our General Disclaimer. OWASP does not endorse or recommend commercial products or services, allowing our community to remain vendor neutral with the collective wisdom of the best minds in software security worldwide. Copyright 2022, OWASP Foundation, Inc. This website uses cookies to analyze our traffic and only share that information with our analytics partners. https://owasp.org/www-project-webgoat/ x Accept 4/4