TERM · SECURITY

OWASP Top 10

What is the OWASP Top 10?

The OWASP Top 10 is a list of the ten most critical categories of security risk in web applications, revised every three to four years by the OWASP Foundation. The current edition dates from 2025, and broken access control tops it again: a user can see or change data they should never reach. It is not a certificate but a shared vocabulary, so a client, a developer and a tester name the same weakness the same way.

Example

An online store with 3,000 registered customers books a security test before the Christmas rush. The report sorts the findings by OWASP Top 10 category:

  • Broken access control. An order opens at /order/10452/. A logged-in customer changes the number to 10451 and sees a stranger’s address and phone number. No hacking tool, just the address bar.
  • Injection. The search box passes text straight to the database (SQL injection), which is enough to pull out the customer list. The review form stores a script that runs in the browser of everyone who opens the product page (cross-site scripting, or XSS), the store’s own staff included.
  • Security misconfiguration. The database admin tool answers on a public address.
  • Software supply chain failures. Two plugins have known vulnerabilities, and the fixes were never installed.

Why it matters for a business

Every category turns into a loss an owner recognises: leaked personal data, other people’s orders on screen, changed prices, a tampered payment page. Leaked customer data also brings GDPR into play: the data protection authority has to be told within 72 hours, unless the breach is unlikely to put anyone at risk. That is why the list earns its place when you commission a site. Ask “is it secure?” and everyone says yes. Ask how each category is handled and only the people who handled it can answer.

A close relative is cross-site request forgery (CSRF). An administrator logged in to the panel opens a hostile page, and that page quietly sends a request in their name, such as creating a new user with full rights. Modern frameworks stop it with a secret token in every form; the thing to check is that the token is actually required.

What to ask

  • Which edition of the OWASP Top 10 was the site tested against, and is there a report with evidence for each finding?
  • How was access checked: can one customer reach another customer’s orders, invoices or profile?
  • How is input checked, in every form, search box, comment field and URL?
  • Who watches plugins and libraries for vulnerabilities, and how soon are fixes installed?

The list exists to raise awareness; OWASP’s verifiable standard is ASVS. So “tested against the OWASP Top 10” in a quote tells you what was looked for, not that the site came back clean. Our website security test runs exactly these attacks against your site (injection, XSS, weak passwords, exposed admin panels) and ends in a report ranked by severity.

A term you do not recognise? Write to us and we will add it.

The glossary grows with the questions we are asked.