OWASP Top 10
The current OWASP Top 10 (2021)
The 2021 edition restructured several categories and introduced three new entries. Each risk category is ordered by prevalence and severity based on real-world data:
1. A01: Broken Access Control – moved from fifth to first position. Occurs when users can act outside their intended permissions. Examples include accessing other users’ accounts, viewing unauthorised data, and modifying access rights. 94% of applications tested showed some form of broken access control.
2. A02: Cryptographic Failures – previously ‘Sensitive Data Exposure.’ Focuses on failures related to cryptography that lead to data exposure. Includes using outdated algorithms (MD5, SHA-1), weak key generation, missing encryption in transit or at rest, and improper certificate validation.
3. A03: Injection – includes SQL injection, NoSQL injection, OS command injection, and LDAP injection. Occurs when untrusted data is sent to an interpreter as part of a command or query. Cross-site scripting (XSS) is now included in this category.
4. A04: Insecure Design – new in 2021. Addresses design-level flaws rather than implementation bugs. A secure by design approach with threat modelling during the design phase prevents this category of risk.
5. A05: Security Misconfiguration – missing security hardening, unnecessary features enabled, default credentials, overly verbose error messages, and misconfigured cloud permissions. Increasingly common as cloud infrastructure grows more complex.
6. A06: Vulnerable and Outdated Components – using libraries, frameworks, or software with known vulnerabilities. This is the supply chain risk within applications – a single outdated dependency can expose the entire application.
7. A07: Identification and Authentication Failures – previously ‘Broken Authentication.’ Covers weak password policies, credential stuffing, missing multi-factor authentication, and session management flaws.
8. A08: Software and Data Integrity Failures – new in 2021. Addresses code and infrastructure that does not protect against integrity violations. Includes insecure CI/CD pipelines, auto-update mechanisms without verification, and deserialisation vulnerabilities.
9. A09: Security Logging and Monitoring Failures – insufficient logging, unmonitored alerts, and missing audit trails. Without proper logging, breaches go undetected. This category connects directly to MXDR and SOC operations.
10. A10: Server-Side Request Forgery (SSRF) – new in 2021. Occurs when a web application fetches a remote resource without validating the user-supplied URL, allowing attackers to reach internal services behind firewalls.
How penetration testers use the OWASP Top 10
The OWASP Top 10 provides a structured methodology for web application penetration testing. Testers systematically assess each category against the target application, using OWASP’s companion resources:
- OWASP Testing Guide – detailed technical procedures for testing each risk category
- OWASP Application Security Verification Standard (ASVS) – a more granular checklist of security requirements, organised by assurance level
- OWASP ZAP – an open-source web application security scanner maintained by OWASP
During a penetration test, the OWASP Top 10 ensures consistent coverage of the most common and impactful web application vulnerabilities. Findings are typically mapped to OWASP categories in the report, giving development teams a recognised reference point for remediation.
OWASP Top 10 for LLMs
In 2023, OWASP published the OWASP Top 10 for Large Language Model Applications, addressing security risks specific to AI systems. This includes prompt injection, insecure output handling, training data poisoning, model denial of service, and supply chain vulnerabilities in AI components. As organisations integrate LLMs into their applications, this newer list extends the OWASP framework into LLM security testing and adversarial AI assessment.
Cyberfort and the OWASP Top 10
Our CREST-certified penetration testers assess web applications against the OWASP Top 10 and the broader OWASP ASVS framework. Whether you need a standalone web application test, an API assessment, or security testing of LLM-integrated applications, our methodology covers the risks that matter most. Discuss your application security testing needs →
Related glossary terms
- OWASP Testing Guide – detailed technical procedures for testing each risk category
- OWASP Application Security Verification Standard (ASVS) – a more granular checklist of security requirements, organised by assurance level
- OWASP ZAP – an open-source web application security scanner maintained by OWASP
During a penetration test, the OWASP Top 10 ensures consistent coverage of the most common and impactful web application vulnerabilities. Findings are typically mapped to OWASP categories in the report, giving development teams a recognised reference point for remediation.
OWASP Top 10 for LLMs
In 2023, OWASP published the OWASP Top 10 for Large Language Model Applications, addressing security risks specific to AI systems. This includes prompt injection, insecure output handling, training data poisoning, model denial of service, and supply chain vulnerabilities in AI components. As organisations integrate LLMs into their applications, this newer list extends the OWASP framework into LLM security testing and adversarial AI assessment.
Cyberfort and the OWASP Top 10
Our CREST-certified penetration testers assess web applications against the OWASP Top 10 and the broader OWASP ASVS framework. Whether you need a standalone web application test, an API assessment, or security testing of LLM-integrated applications, our methodology covers the risks that matter most. Discuss your application security testing needs →
Related glossary terms
- Secure by Design – the development principle that prevents OWASP Top 10 risks at the design stage
- Threat Modelling – the structured approach to identifying application-level threats mapped to OWASP categories
- LLM Security Testing – security assessment of AI applications, informed by OWASP’s Top 10 for LLMs
- CREST Certification – accreditation standard for penetration testing providers
- Supply Chain Cyber Security – the broader risk context for OWASP A06 (vulnerable components) and A08 (integrity failures)
External references
- Wikipedia: OWASP – overview of the OWASP Foundation and its projects
- Wikidata: Q2064897 – canonical entity identifier for the OWASP organisation
- OWASP Top 10: 2021 – the current OWASP Top 10 list with full documentation
- OWASP Top 10 for LLM Applications – OWASP’s security risk list for AI/LLM applications
Frequently asked questions
What is the OWASP Top 10?
The OWASP Top 10 is a list of the ten most critical security risks facing web applications, published by the Open Worldwide Application Security Project. It is based on data from hundreds of organisations and analysis of thousands of real-world applications. The list is updated every three to four years and serves as the baseline reference for web application security testing, secure development training, and procurement requirements. The current version was published in 2021.
Is the OWASP Top 10 a standard or a regulation?
The OWASP Top 10 is an awareness document, not a formal standard or regulation. However, it is widely referenced by regulators, industry bodies, and procurement frameworks. The PCI DSS (Payment Card Industry Data Security Standard) references OWASP in its application security requirements. The ICO references OWASP in data protection guidance. Many organisations require OWASP Top 10 coverage in penetration testing contracts. It functions as a de facto standard even though it is not legally mandated.
What is the difference between the OWASP Top 10 and OWASP ASVS?
The OWASP Top 10 covers the ten most critical risk categories at a high level. The OWASP Application Security Verification Standard (ASVS) is a far more detailed checklist of specific security requirements, organised into three assurance levels. ASVS contains hundreds of individual verification requirements and is designed for thorough security assessments. The Top 10 is an awareness starting point; ASVS is the comprehensive testing framework.
Awards and Accreditations




















Contact Us
Cyberfort Ltd
Venture West,
Greenham Business Park, Thatcham,
Berkshire,
RG19 6HX
