OWASP Top 10 definition
The OWASP Top 10 is a widely used awareness document, published by the Open Worldwide Application Security Project, that lists the ten most critical security risks to web applications. Based on data from real applications and expert input, it is updated every few years and serves as a baseline for secure coding, testing and compliance programs.
What risks does the OWASP Top 10 cover?
Each edition groups vulnerabilities into ten categories ranked by prevalence, exploitability and impact. Category names shift between editions as OWASP refines its data and methods, so always check which version a requirement refers to. The current edition, the OWASP Top 10:2025, contains the categories below. Broken access control stays at the top and now absorbs server-side request forgery (SSRF), while software supply chain failures and mishandling of exceptional conditions are new.
- Broken access control, now including SSRF.
- Security misconfiguration.
- Software supply chain failures, expanding the earlier vulnerable and outdated components category.
- Cryptographic failures.
- Injection, including SQL injection and cross-site scripting.
- Insecure design.
- Authentication failures.
- Software or data integrity failures.
- Security logging and alerting failures.
- Mishandling of exceptional conditions, such as errors that fail open or leak details.
Examples of OWASP Top 10 vulnerabilities
Broken access control appears when a user changes an ID in a URL, from /invoices/1001 to /invoices/1002, and sees another customer's invoice because the server never checks ownership. Injection occurs when user input is inserted into a database query or command without proper handling. Security misconfiguration includes default admin passwords, verbose error messages revealing stack traces, and cloud storage buckets left publicly readable.
Software supply chain failures cover outdated libraries with known exploits, compromised packages and insecure build pipelines, a risk that grows as applications depend on hundreds of open-source packages. Logging failures mean attacks go unnoticed because suspicious activity is never recorded or reviewed. Each of these has a well-documented fix, which is why the list is so useful for training.
How to use the OWASP Top 10
Development teams use the list to focus training and code review on the most damaging mistakes. Security teams map tests to each category during penetration tests and VAPT. Many organizations reference it in secure coding standards, vendor requirements and audit evidence. It works best as a starting point: OWASP's Application Security Verification Standard (ASVS) provides detailed, testable requirements, and the OWASP Cheat Sheet Series gives practical guidance for developers on specific defenses. Map each category to concrete checks.
Other OWASP Top 10 lists
OWASP publishes specialized lists for other technologies. The OWASP API Security Top 10 focuses on risks such as broken object level authorization and excessive data exposure in APIs. There are also lists for mobile applications and for large language model applications, covering risks like prompt injection and sensitive information disclosure, which have become relevant as companies add generative AI features to their products. A newer Top 10 for Agentic Applications covers risks such as goal hijacking, tool misuse and rogue agents in autonomous AI systems. Teams building AI assistants and agents should review these lists alongside the web list, and mobile teams can use OWASP MASVS for detailed requirements.
Limitations of the OWASP Top 10
The Top 10 is an awareness document, not a complete security standard. Passing a test against it does not make an application secure, because business logic flaws, infrastructure weaknesses and risks specific to your domain may fall outside its categories. Treat it as a minimum baseline. Nexzem's application security reviews cover the OWASP Top 10 and ASVS requirements, plus the logic and authorization paths unique to each client's product. Threat modeling fills many of those gaps.