Learning roadmap

Web Security Roadmap

Learn to identify and exploit web application vulnerabilities including XSS, SQL Injection, CSRF, SSRF, and more.

3 Levels

Beginner to Advanced

24 Topics

Across all levels

9 Resources

Labs, courses, books

~6 months

Estimated total

Overall progress0 / 24 topics

0%

Checkboxes are saved in this browser only. Nothing is uploaded.

01

Beginner

4 – 8 weeks
0/7

Topics

Resources

  • PortSwigger Web Security AcademyLab
  • OWASP WebGoatLab
  • TryHackMe Web FundamentalsCourse
02

Intermediate

8 – 16 weeks
0/8

Topics

Resources

  • PortSwigger Labs (all topics)Lab
  • PentesterLabLab
  • Hack The Box Web ChallengesLab
03

Advanced

12 – 24 weeks
0/9

Topics

Resources

  • HackTricks WebReference
  • Bug Bounty ProgramsPractice
  • Real-world CVE analysisResearch

Tools you'll use

See all for this track

Ready to go deeper?

Read the full Web Security track, or test yourself with the quiz.