Skip to main content
Book 07 · SecurityPage 24 of 50

OWASP Top 10

Pronunciation
OH-wasp top TEN
Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/owasp-top-10

In short

The OWASP Top 10 is a widely used list of the ten most critical security risks to web applications, published by the nonprofit OWASP and updated regularly.

What is the OWASP Top 10?

The OWASP Top 10 is an awareness document that ranks the most serious categories of web application security risks. It is published by OWASP, the Open Worldwide Application Security Project, a nonprofit community that produces free security guides and tools. Each category, such as broken access control, injection, or security misconfiguration, groups many specific weaknesses under one name and explains how to prevent them.

The list is built from vulnerability data contributed by security companies and organizations, combined with a survey of practitioners, so it reflects both how often a problem is found and how much damage it can do. It is updated every few years, and broken access control, where users can reach data or actions they should not, held the top spot in both the 2021 and 2025 editions. The 2025 edition also broadened the old category about vulnerable components into software supply chain failures, reflecting the rise of attacks through dependencies and build systems.

Teams use the OWASP Top 10 as a starting checklist for secure coding training, code reviews, security testing, and procurement requirements, and many standards and audits refer to it. It works like a list of the most common causes of house fires: it doesn't cover every hazard, but fixing the top items prevents a large share of real incidents. For deeper, testable requirements, OWASP also publishes the Application Security Verification Standard (ASVS), and there are separate Top 10 lists for APIs, mobile apps, and LLM applications.

The OWASP Top 10 is often confused with the CVE list. A CVE entry identifies one specific vulnerability in a particular product, such as one bug in one version of a library, while the OWASP Top 10 describes broad categories of mistakes that could appear in any application. Passing a Top 10 checklist also doesn't make an application secure; it is a minimum baseline, not a complete standard.

Key takeaways

  • The OWASP Top 10 ranks the most critical categories of web application security risks.
  • It is published by OWASP, a nonprofit, and updated every few years from real-world data.
  • Broken access control is currently the top risk.
  • It is an awareness baseline, not a complete security standard.
  • CVEs identify specific vulnerabilities; the Top 10 describes broad categories of weaknesses.

Example

Broken access control, the top risk, and its fixjavascript
// Vulnerable: any signed-in user can read any invoice by changing the ID
app.get("/invoices/:id", requireSignIn, async (req, res) => {
  const invoice = await db.invoices.findById(req.params.id);
  res.json(invoice); // never checks who owns it
});

// Fixed: confirm the invoice belongs to the current user
app.get("/invoices/:id", requireSignIn, async (req, res) => {
  const invoice = await db.invoices.findById(req.params.id);
  if (!invoice || invoice.ownerId !== req.user.id) return res.sendStatus(404);
  res.json(invoice);
});

Readers ask

What is number one on the OWASP Top 10?

Broken access control is the top risk in both the 2021 and 2025 editions. It covers flaws that let users view or change data or perform actions beyond their permissions, such as reading another user's records by changing an ID in the URL.

How often is the OWASP Top 10 updated?

Roughly every three to four years. Recent editions were published in 2017, 2021, and 2025, each based on newly collected vulnerability data and community input.

Is the OWASP Top 10 a compliance standard?

No, it is an awareness document, although some standards and contracts reference it. For detailed, verifiable requirements, teams use the OWASP Application Security Verification Standard (ASVS).

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings