What is the OWASP Top 10?
The OWASP Top 10 is an awareness document: a ranked list of the ten web application risk categories OWASP considers most critical, first published in 2003. The current edition is the OWASP Top 10:2025, which replaced the 2021 list. Each entry is a category, not a single bug. A01:2025 Broken Access Control, for example, groups 40 CWE weaknesses, from path traversal to server-side request forgery.
The 2025 list mixes data and opinion by design. OWASP collected testing data covering 589 CWEs and ranked candidate categories from it, then used a community survey to promote two risks the data underrepresents, because testing data reflects what tools already find. Security Logging and Alerting Failures, for instance, is always underrepresented in data and was voted onto the list.
What are the 2025 categories?
| 2025 entry | Closest 2021 entry | CVEs mapped |
|---|---|---|
| A01:2025 Broken Access Control | A01:2021 Broken Access Control, plus A10:2021 SSRF | 32,654 |
| A02:2025 Security Misconfiguration | A05:2021 Security Misconfiguration | 1,375 |
| A03:2025 Software Supply Chain Failures | A06:2021 Vulnerable and Outdated Components, expanded | 11 |
| A04:2025 Cryptographic Failures | A02:2021 Cryptographic Failures | 2,185 |
| A05:2025 Injection | A03:2021 Injection | 62,445 |
| A06:2025 Insecure Design | A04:2021 Insecure Design | 7,647 |
| A07:2025 Authentication Failures | A07:2021 Identification and Authentication Failures | 7,147 |
| A08:2025 Software or Data Integrity Failures | A08:2021 Software and Data Integrity Failures | 3,331 |
| A09:2025 Security Logging and Alerting Failures | A09:2021 Security Logging and Monitoring Failures | 723 |
| A10:2025 Mishandling of Exceptional Conditions | New | 3,416 |
The CVE counts come from each category's score table on owasp.org and show why rank is not the same as volume. Injection has by far the most CVEs and sits at fifth; Software Supply Chain Failures has 11 and sits at third, because practitioners rated it a top concern that testing does not yet measure well.
The changes from 2021 worth knowing:
- SSRF is no longer its own entry. It was rolled into A01. A report that files SSRF under "A10" is using the 2021 list.
- Vulnerable components became supply chain. A03 now covers compromises across dependencies, build systems and distribution, not only outdated libraries.
- A10 is new. Mishandling of Exceptional Conditions covers improper error handling, failing open and logic errors triggered by abnormal states.
- Two renames. A07 dropped "Identification", and A09 swapped "Monitoring" for "Alerting".
What are the sibling lists?
OWASP publishes separate Top 10s because APIs and LLM applications fail in ways the web list does not rank.
The API Security Top 10 2023 is the current API edition:
| ID | Risk |
|---|---|
| API1:2023 | Broken Object Level Authorization |
| API2:2023 | Broken Authentication |
| API3:2023 | Broken Object Property Level Authorization |
| API4:2023 | Unrestricted Resource Consumption |
| API5:2023 | Broken Function Level Authorization |
| API6:2023 | Unrestricted Access to Sensitive Business Flows |
| API7:2023 | Server Side Request Forgery |
| API8:2023 | Security Misconfiguration |
| API9:2023 | Improper Inventory Management |
| API10:2023 | Unsafe Consumption of APIs |
Three of the ten are authorization failures at different granularities: object (BOLA), property, and function.
The GenAI LLM Top 10 2026, published by the OWASP GenAI Security Project on August 4, 2026, replaced the 2025 LLM list:
| ID | Risk |
|---|---|
| LLM01:2026 | Prompt Injection |
| LLM02:2026 | Sensitive Information Disclosure |
| LLM03:2026 | Excessive Agency |
| LLM04:2026 | Supply Chain |
| LLM05:2026 | Data and Model Poisoning |
| LLM06:2026 | Unbounded Consumption |
| LLM07:2026 | Misinformation |
| LLM08:2026 | Hidden Context Exposure |
| LLM09:2026 | Vector and Embedding Weaknesses |
| LLM10:2026 | Improper Output Handling |
Compared with 2025, Excessive Agency climbed from sixth to third, Improper Output Handling fell from fifth to tenth, and System Prompt Leakage was broadened into Hidden Context Exposure. Prompt injection stays first. For systems where the model calls tools and takes actions, the same project also publishes a Top 10 for Agentic Applications (first released December 9, 2025), with entries numbered ASI01 to ASI10.
One finding, classified three ways
The lists overlap, so a finding usually carries several labels. A single broken ownership check on GET /api/v1/projects/2210, where user_a can read tenant_b's project, is:
- A01:2025 Broken Access Control in the web Top 10,
- API1:2023 Broken Object Level Authorization in the API Top 10,
- CWE-639 Authorization Bypass Through User-Controlled Key, the root-cause ID (see how CWE mapping works).
A report should cite the edition in every label. "A01" alone is ambiguous between 2021 and 2025, and A10 means SSRF in one edition and exceptional conditions in the next.
How do teams use it, and misuse it?
OWASP is blunt about what the list is for. The 2025 edition calls it primarily an awareness document, warns that using it as a coding or testing standard is "the bare minimum", and notes a structural limit: it documents risks, not easily testable issues. Insecure design, for example, is beyond the scope of most forms of testing.
Good uses:
- Training and onboarding. A shared vocabulary for developers who are new to application security.
- Threat modeling prompts. Walking a design through the ten categories surfaces questions ("where are authorization decisions made?") early.
- Report taxonomy. Tagging findings with an edition-labeled category lets you trend them across tests.
Common misuses:
- Treating it as a checklist. Ten green ticks say nothing about business logic flaws, which rarely fit a category cleanly, or about risks the list does not rank.
- Buying "full Top 10 coverage". OWASP discourages any claim of full coverage of the Top 10, and says tool vendors should use the Application Security Verification Standard (ASVS) instead.
- Using it as the requirement. For verifiable security requirements, OWASP recommends ASVS. OWASP's Web Security Testing Guide covers how to test.
- Scoping a test to the list. A penetration testing methodology that stops at ten categories stops before the bugs specific to your application.
[ Sources ]
Written by Parameter · Last reviewed

