Pikachu is a web application system with vulnerabilities, which contains common web security vulnerabilities. If you are a web penetration testing learner and are worried about not having a suitable shooting range to practice, then Pikachu may be just for you. “If you want to understand a vulnerability, the better way is: you can create the vulnerability yourself (in code), then exploit it, and finally fix it.” The list of vulnerability types on Pikachu is as follows: Burt Force (brute force vulnerability) XSS (cross-site scripting vulnerability) CSRF (cross-site request forgery) SQL-Inject (SQL injection vulnerability) RCE (remote command…

