What is OWASP Top 10?
Definition
The OWASP Top 10 is an awareness document from the non-profit OWASP community that ranks the ten most critical security risk categories for web applications. The current edition is the 2025 release, with broken access control in first place. Categories are chosen from security testing data contributed by organisations plus a practitioner survey. It is a starting point for prioritising work, not a certification or a testing standard.
Also known as: OWASP Top Ten, OWASP Top 10:2025, OWASP Top 10 2025, OWASP risks

What it is, and what it is not
OWASP (the Open Worldwide Application Security Project) is a foundation that runs open-source application security projects. The Top 10 is its best-known output and, in its own words, a standard awareness document for developers. The 2025 release is the eighth edition. Eight of its ten categories are selected from contributed data covering more than 2.8 million applications; the remaining two come from a community survey meant to capture risks that testing data does not yet reflect.
It is not a testing standard. “Our app is OWASP Top 10 compliant” says nothing measurable on its own. For verifiable requirements, OWASP maintains the Application Security Verification Standard (ASVS); for test procedures, the Web Security Testing Guide.
The 2025 list
| Code | Category | In short |
|---|---|---|
| A01 | Broken Access Control | Users reaching data or actions they should not; now includes SSRF. |
| A02 | Security Misconfiguration | Debug modes left on, default credentials, unnecessary services. |
| A03 | Software Supply Chain Failures | Risks arriving through dependencies, build systems and distribution infrastructure. |
| A04 | Cryptographic Failures | Weak or misused cryptography, sensitive data stored unprotected. |
| A05 | Injection | Untrusted input interpreted as a query or code, including XSS and SQL injection. |
| A06 | Insecure Design | Flaws introduced at design time, before any code is written. |
| A07 | Authentication Failures | Weak login, session and account recovery mechanisms. |
| A08 | Software or Data Integrity Failures | Updates, scripts and data used without verifying their integrity. |
| A09 | Security Logging and Alerting Failures | Missing logs and alerts that would reveal an attack. |
| A10 | Mishandling of Exceptional Conditions | Poor error handling, logic errors, failing open. |
What changed since 2021
- Access control stays at number one, now absorbing server-side request forgery, which was a separate category in 2021. Authorization flaws remain the most common serious risk.
- Security Misconfiguration climbs from #5 to #2, reflecting how much application behaviour is now driven by configuration.
- The supply chain category widens. 2021's “Vulnerable and Outdated Components” becomes A03, covering build and distribution systems as well as dependencies. It has limited presence in the data but was the community survey's top concern.
- Injection drops from #3 to #5, yet remains the most tested category with the most associated CVEs; XSS and SQL injection live here.
- A10 is new, grouping error handling, logic errors and systems that fail open.
Putting it to work
The list earns its keep as shared vocabulary: onboarding developers, prompting code reviewers, framing threat-modelling questions (“which category does this feature put at risk?”) and classifying findings. That is why penetration test reports commonly map their findings to Top 10 categories.
Know its limits, too. Each category bundles dozens of weakness types (CWEs), so it cannot be ticked off like a checklist. When working with a vendor, asking which ASVS level they target and how it will be verified sets a far more concrete expectation than “Top 10 compliance”. Full category write-ups are published at OWASP Top 10:2025.

