Wiki

What Is the OWASP Top 10? A Practical Guide to the Most Critical Web Application Security Risks

A reference guide for QA engineers and developers explaining what the OWASP Top 10 is, how it is compiled, what the 2025 list contains, and how to use it in secure software development and testing.

On this page

Introduction

The OWASP Top 10 is a standard awareness document for developers and web application security. According to the OWASP Foundation, it represents a broad consensus about the most critical security risks to web applications and is globally recognized by developers as the first step towards more secure coding. The Open Worldwide Application Security Project (OWASP) is a non-profit foundation focused on improving the security of software, best known for openly published resources, community-driven projects, and practical guidance that developers and security teams can use without a paywall.

For most software developers, the OWASP Top 10 is their first touchpoint with OWASP. However, OWASP maintains far more than a single list: cheat sheets, testing guides, and verification standards that help teams build secure software from design through deployment.

What Is the OWASP Top 10?

The OWASP Top 10 is a widely recognized awareness document that highlights the most critical risks in web application security, from broken access control and cryptographic failures to server-side request forgery, data integrity failures, and weaknesses in security logging and monitoring. Designed primarily for developers, it helps teams protect sensitive data and strengthen software security by focusing on the vulnerabilities that most commonly lead to real-world breaches.

The goal is to give teams a shared mental model of the most common, most impactful vulnerabilities so they can prioritize secure coding training. Addressing these categories helps reduce recurring security vulnerabilities and improve code resilience.

How the List Is Compiled

The OWASP Top 10 security risks are updated usually every four years and are based on the severity of vulnerabilities, compiled with inputs received from thousands of real security professionals around the world. The list is based on real data. All major companies, government agencies, and security professionals take it very seriously as it reflects actual breach data. Payment card standards require it, security certifications test on it, and auditors evaluate web security against it.

One source states that the list covers roughly 80% of web application security risks, making it an effective starting point for prioritizing protection efforts. However, the list covers the most critical risks but not all of them. Modern AppSec programs layer OWASP Top 10 coverage with software supply chain security, AI-generated code risk, CI/CD pipeline integrity, and secrets exposure — attack surfaces that the 2021 edition predates.

Why It Matters for QA and Development Teams

Veracode's State of Software Security 2025, which scanned over one million applications, revealed that nearly half contained at least one security flaw listed in the OWASP Top 10. This underscores the need for secure coding practices and emphasizes the importance of frequent and thorough testing.

According to the OWASP Foundation, adopting the OWASP Top 10 is perhaps the most effective first step towards changing your software development culture into one focused on producing secure code. OWASP encourages widespread adoption of the Top 10 as a foundational element of secure software development lifecycle (SDLC) practices.

The OWASP Top 10: 2025 List

The most current released version is the OWASP Top 10 2025. Previous versions are available as OWASP Top 10 2021 and OWASP Top 10 2017. The 2025 list reflects how modern application risk is shifting from isolated coding flaws to the security of the entire software ecosystem.

Compared to 2021, the new OWASP list highlights several new security risks. This update reshapes priorities for developers, security teams, and organizations building modern software.

What's New in 2025

Two notable additions to the 2025 list are:

  • Software Supply Chain Failures (A03): This new risk explains risks across the entire software lifecycle, including dependencies, build systems, CI/CD pipelines, and third-party platforms, not just known vulnerable libraries.
  • Mishandling of Exceptional Conditions (A10): Added as a completely new category, focusing on poor error handling, unsafe failure states, and unhandled exceptions.

The supplied excerpts do not provide the complete ordered 2025 list. They reference the following categories from the OWASP Top 10, though the exact numbering for all items in the 2025 edition is not fully specified in the source material:

  1. Broken Access Control
  2. Cryptographic Failures
  3. Injection attacks
  4. Insecure Design
  5. Security Misconfiguration
  6. Vulnerable and Outdated Components
  7. Identification and Authentication Failures
  8. Software and Data Integrity Failures
  9. Security Logging and Monitoring Failures
  10. Server-Side Request Forgery (SSRF)

The Ten Categories in Detail

1. Broken Access Control

Broken access control refers to failures in enforcing restrictions on what authenticated users are allowed to do. The excerpts list this as the first category but do not provide detailed prevention guidance or examples for it.

2. Cryptographic Failures

Cryptographic failures occur when sensitive data is not properly protected through encryption and other cryptographic controls. The excerpts identify common causes, preventions, and examples as existing sections but do not include the specific content of those sections.

3. Injection Attacks

Injection attacks occur when untrusted data is sent to an interpreter as part of a command or query. The excerpts reference common types of injection attacks, preventions, and examples but do not enumerate them in the provided text.

4. Insecure Design

Insecure design represents risks related to design and architectural flaws. The excerpts list preventions and examples as sections but do not provide their specific content.

5. Security Misconfiguration

Security misconfiguration covers improperly configured security settings across the application stack. The excerpts reference preventions and examples but do not include the detailed content.

6. Vulnerable and Outdated Components

This category addresses risks from using components with known vulnerabilities or outdated versions. The excerpts list prevention and examples sections but do not provide their specific content.

7. Identification and Authentication Failures

This category covers failures in confirming user identity and managing authentication sessions. The excerpts reference types of failures, prevention, and examples but do not include the detailed content.

8. Software and Data Integrity Failures

Software and data integrity failures relate to code and infrastructure that does not protect against integrity violations. The excerpts mention understanding integrity, common integrity threats, prevention, and examples as sections but do not provide their specific content.

9. Security Logging and Monitoring Failures

Security logging and monitoring failures occur when security-relevant events are not logged, monitored, or alerted on properly. The excerpts reference common failures in logging and monitoring, prevention, and examples but do not include the detailed content.

10. Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF) occurs when a web application fetches a remote resource without validating the user-supplied URL. The excerpts reference SSRF types, prevention, additional measures, and examples but do not include the detailed content.

Using the OWASP Top 10 in QA and Development

For Developers

OWASP encourages widespread adoption of the Top 10 as a foundational element of secure software development lifecycle (SDLC) practices. Companies should adopt this document and start the process of ensuring that their web applications minimize these risks.

For QA Engineers

The excerpts do not provide specific guidance on how QA engineers should test against the OWASP Top 10. However, the document serves as a shared mental model of common vulnerabilities, which can inform test planning and security test case design. OWASP also maintains testing guides that teams can use, though the excerpts do not detail their contents.

Limitations of the List

The list covers the most critical risks but not all of them. The vulnerabilities attackers exploit today extend beyond what any single list captured three years ago. Teams should treat the OWASP Top 10 as a starting point rather than a complete security program.

Final Words

The OWASP Top 10 provides a standardized catalog of the most critical security risks to web applications. Compiled by a global community of security experts, this influential document highlights the most prevalent vulnerabilities that organizations must address. For QA engineers and developers, it offers a shared vocabulary and prioritization framework for building and testing more secure web applications.

Sources

Public pages this article was researched from.