Learning roadmap
Web Security Roadmap
Learn to identify and exploit web application vulnerabilities including XSS, SQL Injection, CSRF, SSRF, and more.
3 Levels
Beginner to Advanced
24 Topics
Across all levels
9 Resources
Labs, courses, books
~6 months
Estimated total
Overall progress0 / 24 topics
0%
Checkboxes are saved in this browser only. Nothing is uploaded.
01
Beginner
4 – 8 weeks0/7
Topics
Resources
- PortSwigger Web Security AcademyLab
- OWASP WebGoatLab
- TryHackMe Web FundamentalsCourse
02
Intermediate
8 – 16 weeks0/8
Topics
Resources
- PortSwigger Labs (all topics)Lab
- PentesterLabLab
- Hack The Box Web ChallengesLab
03
Advanced
12 – 24 weeks0/9
Topics
Resources
- HackTricks WebReference
- Bug Bounty ProgramsPractice
- Real-world CVE analysisResearch
Tools you'll use
See all for this trackReady to go deeper?
Read the full Web Security track, or test yourself with the quiz.