The Broken Web Applications (BWA) Project produces a Virtual Machine running a variety of applications with known vulnerabilities for those interested in:
all the while saving people interested in doing either learning or testing the pain of having to compile, configure, and catalog all of the things normally involved in doing this process from scratch.
Source: http://owasp.com/index.php/OWASP_Broken_Web_Applications_Project
Release notes for the Open Web Application Security Project (OWASP) Broken Web Applications Project, a collection of vulnerable web applications that is distributed on a Virtual Machine in VMware format compatible with their no-cost and commercial VMware products.
More information about the project can be found at http://www.owaspbwa.org/.
The VM can be downloaded as a .zip file or as a much smaller .7z 7-zip Archive. BOTH FILES CONTAIN THE EXACT SAME VM! We recommend that you download the .7z archive if possible to save bandwidth (and time). 7-zip is available for Windows, Mac, Linux, and other Operating Systems.
!!! This VM has many serious security issues. We strongly recommend that you run it only on the "host only" or "NAT" network in the virtual machine settings !!!
Version 1.2 - 2015-08-03
Version 1.2rc1 - 2015-06-24
Version 1.1.1 - 2013-09-27
Version 1.1 - 2013-07-30
Version 1.1beta1 - 2013-07-10
Version 1.0 - 2012-07-24
Version 1.0rc2 - 2012-07-14
Version 1.0rc1 - 2012-04-04
Version 0.94 - 2011-07-24
Version 0.94rc3 - 2011-07-14
Version 0.94rc2 - 2011-07-13
Version 0.94rc1 - 2011-07-11
Version 0.93rc1 - 2011-01-19
Version 0.92rc2 - 2010-11-15
Version 0.92rc1 - 2010-11-10
Version 0.91rc1 - 2010-03-24
Version 0.9 - 2009-11-11