Home/Blog/Security Essentials
Security Essentials

OWASP Top 10 Explained: What It Is and How to Use It in Testing

The OWASP Top 10 is the most widely recognised short list of web application security risks. Developers use it for training, buyers see it in proposals, and auditors sometimes ask whether testing covered it. It is useful for all three, as long as nobody mistakes it for a complete standard.

This guide explains what the list is, summarises the ten categories in the current 2025 edition, and shows how to use it when you build software or commission a penetration test. If you already know the list and want to know what changed from 2021, read OWASP Top 10 2025: what changed.

At a glance

  • OWASP (the Open Worldwide Application Security Project) is a non-profit foundation that publishes free, community-built security resources.
  • The Top 10 is an awareness document. It ranks broad risk categories using contributed testing data and a community survey.
  • The current edition is the OWASP Top 10:2025, which replaced the 2021 list.
  • Use it to prioritise training and to check test coverage. Use the OWASP ASVS for detailed requirements and the Web Security Testing Guide for test method.
  • A report that says "OWASP Top 10 tested" should show what was tested in each category, not just the label.

Who OWASP are

OWASP is an open community rather than a vendor or a regulator. Its projects are written and maintained by volunteers, and everything is free to use. Alongside the Top 10, the best-known projects include the Application Security Verification Standard (ASVS), the Web Security Testing Guide (WSTG), the Cheat Sheet Series, and separate Top 10 lists for APIs and for large language model applications.

That matters because the Top 10 is one entry point into a much larger body of guidance. It tells you which classes of weakness are common and serious. The other projects tell you how to prevent and test for them.

The OWASP Top 10:2025 in plain English

IDCategoryWhat it means in practice
A01Broken Access ControlUsers can see or change data and functions they should not. Server-side request forgery (SSRF) now sits here too.
A02Security MisconfigurationInsecure defaults, exposed admin interfaces, verbose errors and weak cloud or header settings.
A03Software Supply Chain FailuresRisk from dependencies, build pipelines and distribution, not just outdated libraries with known CVEs.
A04Cryptographic FailuresSensitive data exposed through weak, missing or misused encryption.
A05InjectionUntrusted input interpreted as code or commands, including SQL injection and cross-site scripting.
A06Insecure DesignFlaws in the design itself, such as missing limits on business workflows, that clean code alone cannot fix.
A07Authentication FailuresWeak login, session and credential handling, including missing protection against credential stuffing.
A08Software or Data Integrity FailuresTrusting code, updates or data without checking integrity, including unsafe deserialisation.
A09Security Logging and Alerting FailuresAttacks happen without useful logs or without anyone being alerted.
A10Mishandling of Exceptional ConditionsSystems that fail open, leak detail or behave unsafely when errors and edge cases occur.

The wording above is a summary. Check category definitions on the official OWASP Top 10:2025 site before quoting them in policy or procurement documents.

How developers should use it

The list works best as a teaching tool and a prioritisation aid:

  1. Training: walk teams through each category with examples from your own stack.
  2. Design reviews: ask which categories a new feature could introduce, especially access control and insecure design.
  3. Requirements: turn categories into testable requirements using the OWASP ASVS, which goes far deeper than ten headings.
  4. Prevention guidance: point developers to the relevant cheat sheets, for example our summaries of authentication and input validation.

Ten categories cannot describe every risk in a real application. Business logic, multi-tenant isolation and abuse of legitimate features often matter more than the ranking suggests.

How buyers should use it in a penetration test

When you commission web application testing, the Top 10 is a reasonable coverage check, not a scope definition.

  • Ask the supplier which methodology they follow. The WSTG is the usual reference for web applications.
  • Check that access control testing uses real accounts for each role you care about. Broken access control is first on the list, and it cannot be tested properly without credentials.
  • If your product is API-heavy, ask for coverage against the OWASP API Security Top 10 as well. The web list does not cover object-level authorisation on APIs in enough depth.
  • If you are adding AI features, the OWASP Top 10 for LLM applications applies to those components.
  • In the report, look for findings mapped to categories with evidence, and a note of which categories were tested with no exploitable issue found.

What the Top 10 cannot do for you

  • It is not a compliance standard or a certification. Nobody "passes" the OWASP Top 10.
  • A clean result against ten categories does not mean an application is secure. It means no exploitable issue was found in those areas, within the scope and time tested.
  • Rankings reflect contributed data across many organisations. Your own risk depends on your architecture, data and users.
  • Material that still quotes the 2021 list is not wrong about the underlying weaknesses, but category names and groupings have changed. Map old findings to 2025 categories before reporting trends.

Attack Vector identifies security weaknesses in agreed scopes and reports them so your team can prioritise remediation. We do not take over fixing your application as part of the test.

For an indicative estimate, use the instant quote calculator or email [email protected]. Engagements start from £1,500 for a small, well-defined job.

FAQ

Is the OWASP Top 10 mandatory?

No. It is guidance. Some customer questionnaires and security policies reference it as an example of recognised good practice, so it often appears in contracts and tenders, but it is not a legal requirement in itself.

How often is the list updated?

Every few years. Editions appeared in 2003, 2004, 2007, 2010, 2013, 2017, 2021 and 2025. Check the official site for the current edition before citing it.

Does a penetration test cover all ten categories?

A web application test should consider all of them where they apply, but depth varies with scope, roles provided and time. Some categories, such as supply chain failures and logging, are only partly testable from outside and may need configuration or code review as well.

What is the difference between the Top 10 and the ASVS?

The Top 10 is a short awareness list of risk categories. The ASVS is a detailed set of security requirements you can design and test against, organised into levels. Use the Top 10 to prioritise and the ASVS to verify.

Is there a separate list for APIs?

Yes. The OWASP API Security Top 10 (2023) covers API-specific risks such as broken object level authorisation. See API vs web application penetration testing for when you need each.

Suggested Resources

#owasp#web-application-security#security-essentials

Ready to strengthen your security?

Talk to our consultants about your penetration testing requirements, or get a fast, transparent quote.