Skip to content

What is OWASP Top 10?

Cybersecurity & Compliance, explained by the engineers who build it. Definition, how it works, use cases and common questions.

OWASP Top 10 definition

The OWASP Top 10 is a widely used awareness document, published by the Open Worldwide Application Security Project, that lists the ten most critical security risks to web applications. Based on data from real applications and expert input, it is updated every few years and serves as a baseline for secure coding, testing and compliance programs.

What risks does the OWASP Top 10 cover?

Each edition groups vulnerabilities into ten categories ranked by prevalence, exploitability and impact. Category names shift between editions as OWASP refines its data and methods, so always check which version a requirement refers to. The current edition, the OWASP Top 10:2025, contains the categories below. Broken access control stays at the top and now absorbs server-side request forgery (SSRF), while software supply chain failures and mishandling of exceptional conditions are new.

  • Broken access control, now including SSRF.
  • Security misconfiguration.
  • Software supply chain failures, expanding the earlier vulnerable and outdated components category.
  • Cryptographic failures.
  • Injection, including SQL injection and cross-site scripting.
  • Insecure design.
  • Authentication failures.
  • Software or data integrity failures.
  • Security logging and alerting failures.
  • Mishandling of exceptional conditions, such as errors that fail open or leak details.

Examples of OWASP Top 10 vulnerabilities

Broken access control appears when a user changes an ID in a URL, from /invoices/1001 to /invoices/1002, and sees another customer's invoice because the server never checks ownership. Injection occurs when user input is inserted into a database query or command without proper handling. Security misconfiguration includes default admin passwords, verbose error messages revealing stack traces, and cloud storage buckets left publicly readable.

Software supply chain failures cover outdated libraries with known exploits, compromised packages and insecure build pipelines, a risk that grows as applications depend on hundreds of open-source packages. Logging failures mean attacks go unnoticed because suspicious activity is never recorded or reviewed. Each of these has a well-documented fix, which is why the list is so useful for training.

How to use the OWASP Top 10

Development teams use the list to focus training and code review on the most damaging mistakes. Security teams map tests to each category during penetration tests and VAPT. Many organizations reference it in secure coding standards, vendor requirements and audit evidence. It works best as a starting point: OWASP's Application Security Verification Standard (ASVS) provides detailed, testable requirements, and the OWASP Cheat Sheet Series gives practical guidance for developers on specific defenses. Map each category to concrete checks.

Other OWASP Top 10 lists

OWASP publishes specialized lists for other technologies. The OWASP API Security Top 10 focuses on risks such as broken object level authorization and excessive data exposure in APIs. There are also lists for mobile applications and for large language model applications, covering risks like prompt injection and sensitive information disclosure, which have become relevant as companies add generative AI features to their products. A newer Top 10 for Agentic Applications covers risks such as goal hijacking, tool misuse and rogue agents in autonomous AI systems. Teams building AI assistants and agents should review these lists alongside the web list, and mobile teams can use OWASP MASVS for detailed requirements.

Limitations of the OWASP Top 10

The Top 10 is an awareness document, not a complete security standard. Passing a test against it does not make an application secure, because business logic flaws, infrastructure weaknesses and risks specific to your domain may fall outside its categories. Treat it as a minimum baseline. Nexzem's application security reviews cover the OWASP Top 10 and ASVS requirements, plus the logic and authorization paths unique to each client's product. Threat modeling fills many of those gaps.

OWASP Top 10: common questions

Something else on your mind? Ask a consultant and get a reply within one business day.

What does OWASP stand for?

OWASP stands for the Open Worldwide Application Security Project, previously the Open Web Application Security Project. It is a nonprofit foundation that produces free, open resources for software security, including the Top 10 lists, the Application Security Verification Standard, testing guides, cheat sheets and tools such as OWASP Dependency-Check and OWASP Juice Shop for security testing and training.

Is the OWASP Top 10 a compliance standard?

Not formally. It is an awareness document, but many standards, contracts and auditors reference it as a baseline. PCI DSS, for example, expects protection against common coding vulnerabilities, and the OWASP Top 10 is often used to demonstrate this. For formal, testable requirements, organizations typically adopt OWASP ASVS alongside it.

How often is the OWASP Top 10 updated?

It is updated every few years based on new data contributed by security firms and practitioners, plus a community survey. Categories are merged, renamed or reordered as the threat landscape and testing data change. Always reference the specific edition, since security requirements and reports may be tied to a particular version.

Keep exploring the cybersecurity & compliance glossary

Need OWASP Top 10 in your product?

A solutions consultant replies within one business day with next steps, a rough estimate and a suggested team.