The Open Web Application Security Project (OWASP) is a prominent, non-profit international organisation dedicated to enhancing the security of web applications — and to making its resources freely available to everyone.
Every developer, regardless of their expertise, should invest time in understanding potential code vulnerabilities to prevent problematic and often expensive security mishaps. So what exactly is the OWASP Top 10?
OWASP updates and releases its list of the ten most critical web application vulnerabilities every few years. The list outlines each threat, the potential consequences, and methods to mitigate it. Curated with input from security consultants, vendors and corporate security teams, it stands as a gold standard for best practice in web application security.
In 2021, OWASP introduced a new version of the Top 10, adding three fresh categories, modifying the naming and scope of four, and consolidating others. While its primary objective is to foster awareness, businesses have widely adopted it as an informal benchmark for application security.
The OWASP Top 10 (2021)
- A01 — Broken Access Control (up from #5): reclaims the top spot, appearing in 94% of tested applications and the most critical risk overall.
- A02 — Cryptographic Failures (up from #3): formerly "Sensitive Data Exposure", now focused on the cryptographic failures that lead to data exposure or system compromise.
- A03 — Injection (down from #1): still highly prevalent, tested in 94% of applications; Cross-Site Scripting (XSS) is now included here.
- A04 — Insecure Design (new): emphasises risks from design flaws, encouraging threat modelling, secure design patterns and reference architectures.
- A05 — Security Misconfiguration (up from #6): affects 90% of applications; the former XML External Entities (XXE) category now sits here.
- A06 — Vulnerable and Outdated Components (up from #9): a persistent challenge in testing and risk assessment.
- A07 — Identification and Authentication Failures (down from #2): improved ranking thanks to wider adoption of standardised authentication frameworks.
- A08 — Software and Data Integrity Failures (new): covers assumptions made about updates, critical data and CI/CD pipelines without integrity verification; includes insecure deserialisation.
- A09 — Security Logging and Monitoring Failures (up from #10): crucial for visibility, incident alerting and forensics.
- A10 — Server-Side Request Forgery (SSRF) (new): added on strong community support, reflecting its high exploit and impact potential.
Ready to strengthen your security?
Talk to our consultants about your penetration testing requirements, or get a fast, transparent quote.