Definition · Exposed Web Panels
What is OWASP Top Ten?
The OWASP Top Ten is published by the Open Worldwide Application Security Project, a non-profit software security community. It is a ranked list of broad categories of web application security risk, compiled from contributed vulnerability data across many organisations together with a community survey for issues the data lags behind. New editions appear every few years, and categories are renamed, merged and reordered between them.
What it is and is not
It is an awareness document. OWASP is explicit that the Top Ten is a starting point for understanding risk, not a compliance checklist and not a complete standard — a point worth remembering when a contract or questionnaire demands “OWASP Top Ten compliance”, which is not a state an application can be certified in. For requirements-level detail OWASP publishes the Application Security Verification Standard (ASVS); for testing methodology, the Web Security Testing Guide.
Because categories are groupings rather than specific flaws, two applications can fail the same category for entirely unrelated reasons.
The externally visible categories
Several long-standing categories are at least partly detectable without credentials or source code:
- Security misconfiguration — default settings, verbose errors, missing hardening; see security misconfiguration
- Vulnerable and outdated components — fingerprintable software versions carrying known CVEs
- Identification and authentication failures — exposed login pages, default credentials, no rate limiting; see login fingerprinting
- Injection — often probed for, though confirming it usually means active testing
Others, such as broken access control and insecure design, generally need authenticated or manual testing — the work of DAST, SAST and penetration testing rather than external scanning.
Related concepts
There are companion lists for other domains, including an OWASP API Security Top 10. See also MITRE ATT&CK, which catalogues attacker behaviour rather than software weakness classes, CSP and attack surface reduction.