OWASP Top 10
An awareness document from the Open Worldwide Application Security Project (OWASP) that ranks the ten most critical security risk categories for web applications, based on contributed vulnerability data and a practitioner survey.
The OWASP Top 10 groups common weaknesses into broad risk categories, each mapped to Common Weakness Enumeration (CWE) entries and accompanied by a description, example attack scenarios and prevention guidance. Rankings combine incidence data contributed by organisations that test applications with a survey of practitioners, which allows emerging risks that testing tools struggle to measure to be included.
Development teams, testers and auditors use the list as a baseline for secure coding training, code review checklists and the scope of web application assessments. Security policies and procurement questionnaires often refer to it, and testing tools commonly report findings against its categories. The 2021 edition, for example, placed broken access control first and introduced insecure design, software and data integrity failures, and server-side request forgery as new categories.
The Top 10 is an awareness document, not a complete standard: an application can avoid every listed category and still be insecure. For verifiable requirements, OWASP publishes the Application Security Verification Standard (ASVS), and separate lists cover areas such as APIs and large language model applications. Progress is best tracked as findings per category over time rather than as a pass or fail score.
Key points
- Published by the OWASP Foundation, a non-profit, and revised every few years.
- Each category maps to multiple CWE weaknesses with prevention guidance.
- Broken access control ranked first in the 2021 edition.
- OWASP ASVS provides testable requirements; the Top 10 raises awareness.
Where AiVibe comes in
AiVedha.ai, AiVibe's AI-powered website security audit platform, covers the OWASP Top 10 among more than 170 automated checks and reports findings with severity ratings and remediation steps.
Related terms
- Broken Access ControlCybersecurity & Compliance
- SQL Injection (SQLi)Cybersecurity & Compliance
- Cross-Site Scripting (XSS)Cybersecurity & Compliance
- Security MisconfigurationCybersecurity & Compliance
- Dynamic Application Security Testing (DAST)Cybersecurity & Compliance
- API SecurityCybersecurity & Compliance
Terms that refer to OWASP Top 10
- AI GuardrailsAI & Machine Learning
- API GatewayCloud & AI Infrastructure
- Cross-Site Request Forgery (CSRF)Cybersecurity & Compliance
- Interactive Application Security Testing (IAST)Cybersecurity & Compliance
- Password HashingCybersecurity & Compliance
- Penetration TestingCybersecurity & Compliance
- Prompt InjectionAI & Machine Learning
- Server-Side Request Forgery (SSRF)Cybersecurity & Compliance