Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryWeb Security

OWASP Top 10

The OWASP Top 10 is the awareness list of the most critical web application security risks. The 2021 and 2025 categories, what the list is for, and what it is not.

Updated This page as Markdown

In short

The OWASP Top 10 is a list of the ten most critical categories of web application security risk, published by the Open Worldwide Application Security Project and updated every few years from vulnerability data and a community survey. The 2021 edition starts with Broken Access Control, Cryptographic Failures and Injection; the 2025 edition adds Software Supply Chain Failures. It is an awareness document, not a test standard: for testing, OWASP points to the ASVS and the Web Security Testing Guide.

What is the OWASP Top 10?

The OWASP Top 10 is a ranked list of the ten most critical categories of security risk in web applications. The Open Worldwide Application Security Project compiles it from vulnerability data contributed by testing companies and tool vendors, covering hundreds of thousands of applications, plus a survey of practitioners for risks the data does not show yet. OWASP calls it an awareness document: its job is to give developers, product owners and buyers a common vocabulary for what goes wrong most often.

The 2021 edition lists: A01 Broken Access Control, A02 Cryptographic Failures, A03 Injection, A04 Insecure Design, A05 Security Misconfiguration, A06 Vulnerable and Outdated Components, A07 Identification and Authentication Failures, A08 Software and Data Integrity Failures, A09 Security Logging and Monitoring Failures, A10 Server-Side Request Forgery. The 2025 edition, released for review in November 2025, keeps Broken Access Control at the top, moves Security Misconfiguration to second place and adds Software Supply Chain Failures and Mishandling of Exceptional Conditions as new categories.

Where is it defined?

OWASP publishes the list at owasp.org/Top10 under a Creative Commons licence, with a page per category describing the weakness (mapped to CWE IDs), example attacks and prevention. Each category is a group of CWEs, not a single bug: Broken Access Control in 2021 maps 34 CWEs, from IDOR to path traversal.

Related OWASP projects fill in what the Top 10 leaves out. The Application Security Verification Standard (ASVS) is the checklist of requirements for building and verifying an application. The Web Security Testing Guide (WSTG) describes how to test for each weakness. The API Security Top 10 (2023) covers the API-specific risks a web list misses, above all Broken Object Level Authorization. Regulations rarely cite the Top 10, but the essential requirements of the Cyber Resilience Act (Annex I, Part I) and the secure development measures of NIS2 (Article 21(2)(e)) are what the list helps you meet.

What it means in practice

In web and API penetration tests the Top 10 is a floor, not a ceiling. Our findings cluster the same way OWASP’s data does:

  • Access control is the number one finding for a reason. Missing authorisation checks on object IDs, admin functions reachable by normal users, JWTs that are never validated. Scanners find almost none of these, which is exactly why they top a list built largely from manual tests.
  • Injection has moved. Classic SQL injection has become rarer thanks to ORMs and prepared statements; template injection, command injection in the web interfaces of IoT devices and NoSQL injection have taken its place. Embedded web interfaces on routers, gateways and PLCs are a decade behind.
  • Logging failures only hurt later. Nobody notices the missing audit log until an incident. NIS2 and the CRA both expect you to detect and report; without logs you cannot.

A test “according to OWASP Top 10” is a meaningful minimum for a web application. For a thorough test, ask for ASVS Level 2 coverage and the WSTG test cases that apply.

Common misunderstandings

The OWASP Top 10 is not a compliance standard and not a complete list: an application can be free of all ten categories and still be insecure. It is also specific to web applications. For APIs use the API Security Top 10, for mobile apps the OWASP MASVS, and for embedded devices the OWASP IoT Top 10 and the ISVS. “OWASP certified” does not exist; OWASP certifies nothing, and neither does a testing company.

FAQ

Frequently asked questions

Is a test "according to OWASP Top 10" a complete penetration test?

It is a reasonable minimum for a web application, not a complete test. The Top 10 groups the most common risks; it says nothing about business logic, your specific authorisation model or the API behind the frontend. Ask for ASVS Level 2 coverage and the WSTG test cases that apply to your application.

Which edition should I reference, 2021 or 2025?

Reference the current edition in new contracts and keep the mapping to the old one for existing policies. The categories overlap heavily; what changes is the order and a few new groups such as Software Supply Chain Failures. A tester who knows one edition covers the other.

Does the OWASP Top 10 apply to APIs, mobile apps and IoT devices?

Only partly. OWASP maintains separate lists: the API Security Top 10 (2023) for APIs, the MASVS and Mobile Top 10 for apps, and the IoT Top 10 and ISVS for embedded devices. Web interfaces on devices are covered by the web list, the firmware and protocols are not.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab