About

PwnTheWebsite! is a web security wargame platform focused on reproducing real-world vulnerabilities, bug bounty findings, and CVEs in a controlled environment.

How To?

  • Each challenge contains one or more vulnerabilities to be discovered and exploited.
  • The goal is to obtain the flag by abusing the intended vulnerability.
  • Flags follow the format pwn{...}
  • All challenges run locally using Docker.

Rules

  • Do not perform Denial of Service (DoS) attacks.
  • Do not attack the platform infrastructure.
  • If you find unintended bugs, please report them.

Disclaimer

PwnTheWebsite! is intended for educational purposes only. Any misuse of the knowledge gained here is the sole responsibility of the user.

© 2026 PwnTheWebsite!. All rights reserved.