ctf-web
Covers XSS, SQL injection, template injection, SSRF, XXE, authentication bypass, file uploads, and request smuggling. Also addresses JWT, OAuth/OIDC, SAML, prototype pollution, and smart-contract web surfaces when a web flaw is the main attack path.