Contents

Security › Web Application Security

OWASP Top 10

The ten most critical web application security risks.

Also known as: OWASP Top Ten, OWASP, OWASP Top 10 web application security risks, top 10 vulnerabilities

The OWASP Top 10 is a regularly updated list of the most critical web application security risks, published by the Open Worldwide Application Security Project (OWASP), a non-profit community. It’s an awareness document, widely used as a baseline for secure coding, training and audits, and often referenced in security requirements.

The categories change between editions, based on data and expert input. Over the years, the list has consistently included things like:

Risk areaIn plain wordsLearn more
Broken access controlUsers can act outside their permissions: read others’ data, call admin functionsBroken access control, IDOR
Cryptographic failuresSensitive data unprotected: no TLS, weak algorithms, passwords stored badlyPassword hashing, TLS
InjectionUntrusted input interpreted as commands: SQL, OS commands, templates, and (in older editions) XSSSQL injection, XSS, command injection
Insecure designMissing security thinking in the design itselfThreat modeling
Security misconfigurationDefault passwords, open storage, verbose errors, unneeded featuresSecurity misconfiguration
Vulnerable and outdated componentsKnown-vulnerable libraries and frameworksDependency scanning
Identification and authentication failuresWeak login, session handling and credential recoveryAuthentication, MFA
Software and data integrity failuresUnverified updates, pipelines or serialized dataSupply chain security, insecure deserialization
Security logging and monitoring failuresAttacks go unnoticedAudit logging
Server-side request forgery (SSRF)The server is tricked into making requests on an attacker’s behalfSSRF

(Names and ordering differ between editions. Check the current list at owasp.org.)

How to use it

  • As a checklist for code review and design: for each feature, which of these could apply?
  • As a training outline for new developers: learn what each means and see how it looks in your stack.
  • In requirements and testing: security scanning and penetration tests are often organized around it (SAST, DAST, penetration testing).
  • As a shared vocabulary with security teams.

What it isn’t

  • Not complete. It’s the top ten, not every risk, and it’s not a standard to be “compliant” with.
  • Not a to-do list in order of your priority. Your own threats may differ. Do threat modeling for your system.
  • Not only about code: configuration, dependencies and process matter as much.

OWASP also publishes lists for APIs, mobile and other areas, plus cheat sheets with concrete guidance on how to prevent each issue.