OWASP Top 10
The OWASP Top 10 is the awareness list of the most critical web application security risks. The 2021 and 2025 categories, what the list is for, and what it is not.
Updated This page as Markdown
In short
The OWASP Top 10 is a list of the ten most critical categories of web application security risk, published by the Open Worldwide Application Security Project and updated every few years from vulnerability data and a community survey. The 2021 edition starts with Broken Access Control, Cryptographic Failures and Injection; the 2025 edition adds Software Supply Chain Failures. It is an awareness document, not a test standard: for testing, OWASP points to the ASVS and the Web Security Testing Guide.
What is the OWASP Top 10?
The OWASP Top 10 is a ranked list of the ten most critical categories of security risk in web applications. The Open Worldwide Application Security Project compiles it from vulnerability data contributed by testing companies and tool vendors, covering hundreds of thousands of applications, plus a survey of practitioners for risks the data does not show yet. OWASP calls it an awareness document: its job is to give developers, product owners and buyers a common vocabulary for what goes wrong most often.
The 2021 edition lists: A01 Broken Access Control, A02 Cryptographic Failures, A03 Injection, A04 Insecure Design, A05 Security Misconfiguration, A06 Vulnerable and Outdated Components, A07 Identification and Authentication Failures, A08 Software and Data Integrity Failures, A09 Security Logging and Monitoring Failures, A10 Server-Side Request Forgery. The 2025 edition, released for review in November 2025, keeps Broken Access Control at the top, moves Security Misconfiguration to second place and adds Software Supply Chain Failures and Mishandling of Exceptional Conditions as new categories.
Where is it defined?
OWASP publishes the list at owasp.org/Top10 under a Creative Commons licence, with a page per category describing the weakness (mapped to CWE IDs), example attacks and prevention. Each category is a group of CWEs, not a single bug: Broken Access Control in 2021 maps 34 CWEs, from IDOR to path traversal.
Related OWASP projects fill in what the Top 10 leaves out. The Application Security Verification Standard (ASVS) is the checklist of requirements for building and verifying an application. The Web Security Testing Guide (WSTG) describes how to test for each weakness. The API Security Top 10 (2023) covers the API-specific risks a web list misses, above all Broken Object Level Authorization. Regulations rarely cite the Top 10, but the essential requirements of the Cyber Resilience Act (Annex I, Part I) and the secure development measures of NIS2 (Article 21(2)(e)) are what the list helps you meet.
What it means in practice
In web and API penetration tests the Top 10 is a floor, not a ceiling. Our findings cluster the same way OWASP’s data does:
- Access control is the number one finding for a reason. Missing authorisation checks on object IDs, admin functions reachable by normal users, JWTs that are never validated. Scanners find almost none of these, which is exactly why they top a list built largely from manual tests.
- Injection has moved. Classic SQL injection has become rarer thanks to ORMs and prepared statements; template injection, command injection in the web interfaces of IoT devices and NoSQL injection have taken its place. Embedded web interfaces on routers, gateways and PLCs are a decade behind.
- Logging failures only hurt later. Nobody notices the missing audit log until an incident. NIS2 and the CRA both expect you to detect and report; without logs you cannot.
A test “according to OWASP Top 10” is a meaningful minimum for a web application. For a thorough test, ask for ASVS Level 2 coverage and the WSTG test cases that apply.
Common misunderstandings
The OWASP Top 10 is not a compliance standard and not a complete list: an application can be free of all ten categories and still be insecure. It is also specific to web applications. For APIs use the API Security Top 10, for mobile apps the OWASP MASVS, and for embedded devices the OWASP IoT Top 10 and the ISVS. “OWASP certified” does not exist; OWASP certifies nothing, and neither does a testing company.
FAQ
Frequently asked questions
Is a test "according to OWASP Top 10" a complete penetration test?
It is a reasonable minimum for a web application, not a complete test. The Top 10 groups the most common risks; it says nothing about business logic, your specific authorisation model or the API behind the frontend. Ask for ASVS Level 2 coverage and the WSTG test cases that apply to your application.
Which edition should I reference, 2021 or 2025?
Reference the current edition in new contracts and keep the mapping to the old one for existing policies. The categories overlap heavily; what changes is the order and a few new groups such as Software Supply Chain Failures. A tester who knows one edition covers the other.
Does the OWASP Top 10 apply to APIs, mobile apps and IoT devices?
Only partly. OWASP maintains separate lists: the API Security Top 10 (2023) for APIs, the MASVS and Mobile Top 10 for apps, and the IoT Top 10 and ISVS for embedded devices. Web interfaces on devices are covered by the web list, the firmware and protocols are not.
Sources
Related pages
- GlossaryIDOR / BOLAIDOR (Insecure Direct Object Reference) and BOLA (Broken Object Level Authorization) are one flaw: an API returns objects without checking who asked. Find and fix it.
- GlossarySAST and DASTSAST analyses source code, DAST attacks the running application. What each finds and misses, where they fit in the pipeline, and why neither replaces a penetration test.
- ComparisonsManual vs Automated Penetration Testing: What Tools Find and What People FindAutomated tools find known weaknesses fast and repeatably. Manual testers find logic flaws, chains and anything new. Where the line runs and how to combine both.
- InsightsOWASP API Security Top 10 Explained: What Each Risk Looks LikeThe ten API risks of the OWASP API Security Top 10 (2023 edition), each with a real-world pattern, how we test for it in a pentest and what actually fixes it.
- ServicesYour web app has a login. We check what is behind it.Manual web application and API pentests beyond the scanner: business logic, access control (IDOR, BOLA, BFLA), authentication and OWASP Top 10. Fixed price.
- ServicesSecure code from the first commit.Secure coding training, source code review, threat modelling and DevSecOps. Build secure software and firmware and meet CRA and ISO/SAE 21434 requirements.
