Security · Concept

OWASP Top 10

A regularly updated list of the ten most serious security risks in web applications, published by the non-profit OWASP and used worldwide as a checklist by developers and testers.

Common attacks · updated

How it works

OWASP (the Open Worldwide Application Security Project) is a non-profit community that publishes free security guidance. Its Top 10 is built from data on real application tests plus a survey of practitioners, and it is refreshed every few years. The 2025 edition, in order: broken access control, security misconfiguration, software supply chain failures, cryptographic failures, injection (which covers XSS and SQL injection), insecure design, authentication failures, software or data integrity failures, security logging and alerting failures, and mishandling of exceptional conditions.

Broken access control has held the top spot since 2021. It means a user reaching data or actions that should be off limits, for example seeing someone else's order by changing an id in a URL. The fix is to check permissions on the server for every request, not to hide buttons in the interface.

The Top 10 is an awareness list rather than a full standard. For detailed requirements OWASP publishes the ASVS (Application Security Verification Standard) and the free Cheat Sheet Series, and there are separate Top 10 lists for APIs, mobile apps and LLM applications.

More in Security

Common attacks

All 20 Security terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.