Parameter

OWASP Top 10

Also known as

  • OWASP Top Ten

The OWASP Top 10 is the Open Worldwide Application Security Project's ranked list of the ten most critical web application security risk categories, such as broken access control and injection. The current edition is 2025. Each category groups related CWE weaknesses, and sibling lists cover APIs and LLM applications.

Last reviewed

What is the OWASP Top 10?

The OWASP Top 10 is an awareness document: a ranked list of the ten web application risk categories OWASP considers most critical, first published in 2003. The current edition is the OWASP Top 10:2025, which replaced the 2021 list. Each entry is a category, not a single bug. A01:2025 Broken Access Control, for example, groups 40 CWE weaknesses, from path traversal to server-side request forgery.

The 2025 list mixes data and opinion by design. OWASP collected testing data covering 589 CWEs and ranked candidate categories from it, then used a community survey to promote two risks the data underrepresents, because testing data reflects what tools already find. Security Logging and Alerting Failures, for instance, is always underrepresented in data and was voted onto the list.

What are the 2025 categories?

2025 entryClosest 2021 entryCVEs mapped
A01:2025 Broken Access ControlA01:2021 Broken Access Control, plus A10:2021 SSRF32,654
A02:2025 Security MisconfigurationA05:2021 Security Misconfiguration1,375
A03:2025 Software Supply Chain FailuresA06:2021 Vulnerable and Outdated Components, expanded11
A04:2025 Cryptographic FailuresA02:2021 Cryptographic Failures2,185
A05:2025 InjectionA03:2021 Injection62,445
A06:2025 Insecure DesignA04:2021 Insecure Design7,647
A07:2025 Authentication FailuresA07:2021 Identification and Authentication Failures7,147
A08:2025 Software or Data Integrity FailuresA08:2021 Software and Data Integrity Failures3,331
A09:2025 Security Logging and Alerting FailuresA09:2021 Security Logging and Monitoring Failures723
A10:2025 Mishandling of Exceptional ConditionsNew3,416

The CVE counts come from each category's score table on owasp.org and show why rank is not the same as volume. Injection has by far the most CVEs and sits at fifth; Software Supply Chain Failures has 11 and sits at third, because practitioners rated it a top concern that testing does not yet measure well.

The changes from 2021 worth knowing:

  • SSRF is no longer its own entry. It was rolled into A01. A report that files SSRF under "A10" is using the 2021 list.
  • Vulnerable components became supply chain. A03 now covers compromises across dependencies, build systems and distribution, not only outdated libraries.
  • A10 is new. Mishandling of Exceptional Conditions covers improper error handling, failing open and logic errors triggered by abnormal states.
  • Two renames. A07 dropped "Identification", and A09 swapped "Monitoring" for "Alerting".

What are the sibling lists?

OWASP publishes separate Top 10s because APIs and LLM applications fail in ways the web list does not rank.

The API Security Top 10 2023 is the current API edition:

IDRisk
API1:2023Broken Object Level Authorization
API2:2023Broken Authentication
API3:2023Broken Object Property Level Authorization
API4:2023Unrestricted Resource Consumption
API5:2023Broken Function Level Authorization
API6:2023Unrestricted Access to Sensitive Business Flows
API7:2023Server Side Request Forgery
API8:2023Security Misconfiguration
API9:2023Improper Inventory Management
API10:2023Unsafe Consumption of APIs

Three of the ten are authorization failures at different granularities: object (BOLA), property, and function.

The GenAI LLM Top 10 2026, published by the OWASP GenAI Security Project on August 4, 2026, replaced the 2025 LLM list:

IDRisk
LLM01:2026Prompt Injection
LLM02:2026Sensitive Information Disclosure
LLM03:2026Excessive Agency
LLM04:2026Supply Chain
LLM05:2026Data and Model Poisoning
LLM06:2026Unbounded Consumption
LLM07:2026Misinformation
LLM08:2026Hidden Context Exposure
LLM09:2026Vector and Embedding Weaknesses
LLM10:2026Improper Output Handling

Compared with 2025, Excessive Agency climbed from sixth to third, Improper Output Handling fell from fifth to tenth, and System Prompt Leakage was broadened into Hidden Context Exposure. Prompt injection stays first. For systems where the model calls tools and takes actions, the same project also publishes a Top 10 for Agentic Applications (first released December 9, 2025), with entries numbered ASI01 to ASI10.

One finding, classified three ways

The lists overlap, so a finding usually carries several labels. A single broken ownership check on GET /api/v1/projects/2210, where user_a can read tenant_b's project, is:

  • A01:2025 Broken Access Control in the web Top 10,
  • API1:2023 Broken Object Level Authorization in the API Top 10,
  • CWE-639 Authorization Bypass Through User-Controlled Key, the root-cause ID (see how CWE mapping works).

A report should cite the edition in every label. "A01" alone is ambiguous between 2021 and 2025, and A10 means SSRF in one edition and exceptional conditions in the next.

How do teams use it, and misuse it?

OWASP is blunt about what the list is for. The 2025 edition calls it primarily an awareness document, warns that using it as a coding or testing standard is "the bare minimum", and notes a structural limit: it documents risks, not easily testable issues. Insecure design, for example, is beyond the scope of most forms of testing.

Good uses:

  1. Training and onboarding. A shared vocabulary for developers who are new to application security.
  2. Threat modeling prompts. Walking a design through the ten categories surfaces questions ("where are authorization decisions made?") early.
  3. Report taxonomy. Tagging findings with an edition-labeled category lets you trend them across tests.

Common misuses:

  • Treating it as a checklist. Ten green ticks say nothing about business logic flaws, which rarely fit a category cleanly, or about risks the list does not rank.
  • Buying "full Top 10 coverage". OWASP discourages any claim of full coverage of the Top 10, and says tool vendors should use the Application Security Verification Standard (ASVS) instead.
  • Using it as the requirement. For verifiable security requirements, OWASP recommends ASVS. OWASP's Web Security Testing Guide covers how to test.
  • Scoping a test to the list. A penetration testing methodology that stops at ten categories stops before the bugs specific to your application.

Written by Parameter · Last reviewed

[ related terms ]

Related terms.

Common Weakness Enumeration (CWE)

Common Weakness Enumeration (CWE) is MITRE's catalog of the types of mistakes in software and hardware that lead to vulnerabilities, such as CWE-89 SQL injection or CWE-639 authorization bypass through a user-controlled key.

Broken object level authorization (BOLA)

Broken object level authorization (BOLA) is an API vulnerability where an endpoint accepts an object ID from the client and returns or changes that object without checking the caller owns it, so an attacker swaps in another user's or tenant's ID and reads, edits or deletes their records.

Server-side request forgery (SSRF)

Server-side request forgery (SSRF) is a vulnerability where an attacker makes a server send HTTP requests to a destination of the attacker's choosing, reaching internal services, cloud metadata endpoints, and other hosts the attacker cannot address directly.

Prompt injection

Prompt injection is a vulnerability in applications built on large language models where text supplied by a user, or hidden in a web page, email or document the model reads, is treated as instructions, so an attacker can override the developer's intent and make the model ignore rules, leak context or misuse its connected tools.

Penetration testing methodology

A penetration testing methodology is the documented sequence a tester follows, from scoping and reconnaissance through exploitation, post-exploitation, reporting and retest, usually based on a published standard such as PTES, the OWASP WSTG or NIST SP 800-115, so that coverage is repeatable and results can be compared.