OWASP Top 10
- Pronunciation
- OH-wasp top TEN
In short
The OWASP Top 10 is a widely used list of the ten most critical security risks to web applications, published by the nonprofit OWASP and updated regularly.
What is the OWASP Top 10?
The OWASP Top 10 is an awareness document that ranks the most serious categories of web application security risks. It is published by OWASP, the Open Worldwide Application Security Project, a nonprofit community that produces free security guides and tools. Each category, such as broken access control, injection, or security misconfiguration, groups many specific weaknesses under one name and explains how to prevent them.
The list is built from vulnerability data contributed by security companies and organizations, combined with a survey of practitioners, so it reflects both how often a problem is found and how much damage it can do. It is updated every few years, and broken access control, where users can reach data or actions they should not, held the top spot in both the 2021 and 2025 editions. The 2025 edition also broadened the old category about vulnerable components into software supply chain failures, reflecting the rise of attacks through dependencies and build systems.
Teams use the OWASP Top 10 as a starting checklist for secure coding training, code reviews, security testing, and procurement requirements, and many standards and audits refer to it. It works like a list of the most common causes of house fires: it doesn't cover every hazard, but fixing the top items prevents a large share of real incidents. For deeper, testable requirements, OWASP also publishes the Application Security Verification Standard (ASVS), and there are separate Top 10 lists for APIs, mobile apps, and LLM applications.
The OWASP Top 10 is often confused with the CVE list. A CVE entry identifies one specific vulnerability in a particular product, such as one bug in one version of a library, while the OWASP Top 10 describes broad categories of mistakes that could appear in any application. Passing a Top 10 checklist also doesn't make an application secure; it is a minimum baseline, not a complete standard.
Key takeaways
- The OWASP Top 10 ranks the most critical categories of web application security risks.
- It is published by OWASP, a nonprofit, and updated every few years from real-world data.
- Broken access control is currently the top risk.
- It is an awareness baseline, not a complete security standard.
- CVEs identify specific vulnerabilities; the Top 10 describes broad categories of weaknesses.
Example
// Vulnerable: any signed-in user can read any invoice by changing the ID
app.get("/invoices/:id", requireSignIn, async (req, res) => {
const invoice = await db.invoices.findById(req.params.id);
res.json(invoice); // never checks who owns it
});
// Fixed: confirm the invoice belongs to the current user
app.get("/invoices/:id", requireSignIn, async (req, res) => {
const invoice = await db.invoices.findById(req.params.id);
if (!invoice || invoice.ownerId !== req.user.id) return res.sendStatus(404);
res.json(invoice);
});Readers ask
What is number one on the OWASP Top 10?
Broken access control is the top risk in both the 2021 and 2025 editions. It covers flaws that let users view or change data or perform actions beyond their permissions, such as reading another user's records by changing an ID in the URL.
How often is the OWASP Top 10 updated?
Roughly every three to four years. Recent editions were published in 2017, 2021, and 2025, each based on newly collected vulnerability data and community input.
Is the OWASP Top 10 a compliance standard?
No, it is an awareness document, although some standards and contracts reference it. For detailed, verifiable requirements, teams use the OWASP Application Security Verification Standard (ASVS).
See also
- XSSSecurity, p. 48XSS is a vulnerability that lets an attacker inject malicious JavaScript into a trusted website so that it runs in other users' browsers.
- SQL InjectionSecurity, p. 40SQL injection is an attack where user input is treated as part of a database query, letting an attacker read, change, or delete data they should not reach.
- AuthorizationSecurity, p. 3Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.
- Supply Chain AttackSecurity, p. 43A supply chain attack compromises software through something it relies on, like an open-source package, a build tool or an update server, not the app itself.
- Penetration TestingSecurity, p. 26Penetration testing is an authorized, simulated attack on a system that helps an organization find and fix security weaknesses before real attackers do.
- CVESecurity, p. 9A CVE is a unique public identifier, such as CVE-2021-44228, given to one known security vulnerability so everyone can refer to the same flaw by one name.
- Web Application FirewallSecurity, p. 47A web application firewall (WAF) inspects HTTP requests before they reach a web application and blocks malicious ones, such as SQL injection, based on rules.
- SSRFSecurity, p. 42SSRF is a vulnerability where an attacker makes a server send requests to a destination of their choice, often reaching internal systems they can't access.
- Session HijackingSecurity, p. 38Session hijacking is an attack in which someone steals or guesses a user's session ID or token and uses it to act as that user without knowing their password.
Spotted a mistake or something missing on this page?Suggest an edit