
OWASP Top 10 2025: The Official List, What Changed From 2021, and the LLM Top 10
The OWASP Top 10 is the most cited reference in web application security. Auditors ask for it, compliance frameworks point at it, and every scanner vendor claims to cover it. In 2025 OWASP published two official lists that matter to almost every team: a new edition of the classic OWASP Top 10 2025, replacing the OWASP Top 10 2021, and the OWASP Top 10 for LLM Applications 2025 for anything with a large language model inside it.
This guide covers both official lists side by side. It shows exactly what changed between the OWASP Top 10 2021 and the OWASP Top 10 2025, where to find the official OWASP Top 10 documents (including the LLM technical details), and which parts of each list an automated scan can and cannot check.
OWASP Top 10 quick facts
| List | Current official edition | Previous edition | Official source |
|---|---|---|---|
| OWASP Top 10 (web applications) | OWASP Top 10 2025 | OWASP Top 10 2021 | top10.owasp.org |
| OWASP Top 10 for LLM Applications | 2025 edition (released November 2024) | v1.1 (2023) | genai.owasp.org/llm-top-10 |
| OWASP API Security Top 10 | 2023 edition | 2019 edition | owasp.org/API-Security |
What is the OWASP Top 10?
The OWASP Top 10 is an awareness document maintained by the Open Worldwide Application Security Project, a non-profit foundation. It ranks the ten most critical categories of web application security risk, built from vulnerability data contributed by testing companies and a survey of practitioners. Each OWASP Top 10 entry is a category, not a single bug: one entry such as Injection maps to dozens of specific CWE weaknesses.
Two things the OWASP Top 10 is not: it is not a complete security standard (that is OWASP ASVS), and it is not a certification. Nobody is "OWASP Top 10 certified". When a contract or a security questionnaire asks whether you address the OWASP Top 10, they want evidence that each category was considered and tested. If you want the plain-language version for non-developers, read our OWASP Top 10 guide for website owners.
The official OWASP Top 10 2025 list
The OWASP Top 10 2025 is the eighth edition of the list, released in late 2025. Here is the official OWASP Top 10 2025 ranking, with the category names exactly as OWASP publishes them:
- A01:2025 Broken Access Control. Still number one. Users can reach data or actions they should not, usually by changing an ID or calling an endpoint directly. Server-Side Request Forgery (SSRF) is now folded into this category.
- A02:2025 Security Misconfiguration. Up from fifth place. Insecure defaults, verbose errors, missing security headers, permissive CORS, exposed admin or debug endpoints.
- A03:2025 Software Supply Chain Failures. New name, much wider scope. It replaces "Vulnerable and Outdated Components" and now covers build systems, package registries, CI/CD pipelines and the integrity of everything you ship, not only known CVEs in dependencies.
- A04:2025 Cryptographic Failures. Down from second. Weak or missing encryption in transit and at rest, deprecated TLS, poor key management.
- A05:2025 Injection. Down from third. SQL, NoSQL, OS command and LDAP injection, plus cross-site scripting (XSS).
- A06:2025 Insecure Design. Flaws in how a feature was designed, such as missing rate limits on a password reset flow, that no amount of careful coding fixes.
- A07:2025 Authentication Failures. Renamed from "Identification and Authentication Failures". Credential stuffing, weak session handling, broken MFA and hardcoded credentials.
- A08:2025 Software or Data Integrity Failures. Trusting code, updates or data without verifying them, for example loading a third-party script without Subresource Integrity or deserializing untrusted input.
- A09:2025 Security Logging and Alerting Failures. Renamed from "Logging and Monitoring". The emphasis moved to alerting: logs nobody acts on do not stop a breach.
- A10:2025 Mishandling of Exceptional Conditions. Brand new. Code that fails open, leaks details in error messages, or behaves unsafely when something unexpected happens (a timeout, a null value, an exhausted resource).
OWASP Top 10 2025 vs OWASP Top 10 2021: what changed
If your policies, reports or training still reference the OWASP Top 10 2021, the IDs have moved. The table below maps every OWASP Top 10 2021 category to its place in the OWASP Top 10 2025.
| OWASP Top 10 2021 | OWASP Top 10 2025 | Change |
|---|---|---|
| A01 Broken Access Control | A01 Broken Access Control | Same rank, now includes SSRF |
| A02 Cryptographic Failures | A04 Cryptographic Failures | Down two |
| A03 Injection | A05 Injection | Down two |
| A04 Insecure Design | A06 Insecure Design | Down two |
| A05 Security Misconfiguration | A02 Security Misconfiguration | Up three |
| A06 Vulnerable and Outdated Components | A03 Software Supply Chain Failures | Up three, renamed and widened |
| A07 Identification and Authentication Failures | A07 Authentication Failures | Same rank, renamed |
| A08 Software and Data Integrity Failures | A08 Software or Data Integrity Failures | Same rank |
| A09 Security Logging and Monitoring Failures | A09 Security Logging and Alerting Failures | Same rank, renamed |
| A10 Server-Side Request Forgery | Merged into A01 | Removed as its own entry |
| Not in the 2021 list | A10 Mishandling of Exceptional Conditions | New |
The three changes that matter most
Misconfiguration jumped to second. Modern apps are mostly configuration: cloud settings, headers, CORS, cookie flags, framework defaults. That is good news in one sense, because misconfiguration is the OWASP Top 10 category that external scanning detects most reliably. Guides like fixing missing security headers and fixing CORS misconfiguration address it directly.
Supply chain became a top-three risk. The 2021 entry asked "do you have a dependency with a known CVE?". The OWASP Top 10 2025 version asks whether you can trust your whole pipeline: who can publish to your registry, whether builds are reproducible, whether a compromised GitHub Action could ship malicious code. Dependency scanning is still the starting point (see our software composition analysis guide), but securing your CI/CD pipeline is now squarely inside the OWASP Top 10.
Error handling got its own category. A10:2025 recognises that many breaches start when a system hits an edge case. A payment check that throws and defaults to "approved", or an error page that prints a stack trace with database credentials, both belong here.
The OWASP Top 10 for LLM Applications 2025 (official)
The OWASP Top 10 for LLM Applications is a separate project, now run by the OWASP Gen AI Security Project. The official 2025 edition was published in November 2024 and is still the current version: the "2026 LLM lists" circulating on some blogs are not an official OWASP release at the time of writing. The ten risks are:
- LLM01:2025 Prompt Injection. User input or content the model reads (web pages, documents, emails) changes the model's behaviour in ways you did not intend.
- LLM02:2025 Sensitive Information Disclosure. The model or the app around it reveals personal data, credentials or proprietary information.
- LLM03:2025 Supply Chain. Compromised models, datasets, adapters or packages pulled from public hubs.
- LLM04:2025 Data and Model Poisoning. Tampered training, fine-tuning or embedding data that plants backdoors or bias.
- LLM05:2025 Improper Output Handling. Model output passed to a browser, shell, SQL query or
eval()without validation. This is classic injection, one step removed. - LLM06:2025 Excessive Agency. Agents and tools with more permissions, functions or autonomy than the task needs.
- LLM07:2025 System Prompt Leakage. Secrets or security logic placed in a system prompt that can be extracted.
- LLM08:2025 Vector and Embedding Weaknesses. RAG pipelines that leak data across tenants or accept poisoned documents.
- LLM09:2025 Misinformation. Confident, wrong output that users or downstream systems trust.
- LLM10:2025 Unbounded Consumption. No limits on tokens, requests or cost, leading to denial of service or a surprise bill.
Where is the OWASP Top 10 LLM technical details document?
People often search for an "OWASP Top 10 LLM technical details document". For the 2025 edition there is no separate document with that name. The technical detail lives in the official OWASP Top 10 for LLM Applications 2025 PDF and the matching per-risk pages on genai.owasp.org. Each risk includes a description, common examples of the vulnerability, prevention and mitigation strategies, example attack scenarios, and reference links. That official document is the version to cite in policies and audits. Vendor summaries, including this one, are a starting point, not a substitute.
How the two OWASP Top 10 lists overlap
An LLM feature is still a web application, so both lists apply at once. Several LLM risks are familiar OWASP Top 10 categories in a new setting:
- Improper Output Handling (LLM05) is Injection (A05:2025) where the attacker's payload arrives through the model.
- Supply Chain (LLM03) extends Software Supply Chain Failures (A03:2025) to models and datasets.
- Sensitive Information Disclosure (LLM02) often comes down to an API key or user data exposed through Security Misconfiguration (A02:2025).
- Excessive Agency (LLM06) is Broken Access Control (A01:2025) applied to an agent instead of a user.
- Unbounded Consumption (LLM10) echoes Insecure Design (A06:2025): the missing rate limit is a design decision. Our API security basics guide covers rate limiting in practice.
Testing against the OWASP Top 10: what scanning can and cannot do
No tool "covers the OWASP Top 10" by itself. Some categories show up as externally visible symptoms. Others, like Insecure Design or Broken Access Control, need a human who understands what each user is supposed to be allowed to do. A realistic OWASP Top 10 programme combines three kinds of testing (our static vs dynamic analysis article explains the difference in depth):
- Passive external scanning of the live site for misconfiguration, crypto and integrity issues.
- Code and dependency scanning for supply chain, secrets and risky patterns before deployment.
- Active testing and manual review for access control, injection and business logic.
What Scanverra checks today
The Scanverra security scan is a passive, no-setup scan of a live URL. Its findings are tagged with an OWASP Top 10 category and a CWE. It checks things like TLS and certificate problems, HSTS, CSP and other headers, cookie flags, CORS reflection, mixed content, exposed sensitive files, exposed source maps, GraphQL introspection and public API documentation, open redirects, vulnerable client-side JavaScript libraries and email security records. These map mostly to Security Misconfiguration, Cryptographic Failures, Software Supply Chain Failures and Broken Access Control. Today those tags use the OWASP Top 10 2021 IDs (for example A05:2021 for misconfiguration), so use the table above to translate them to the OWASP Top 10 2025 numbering.
The repository scanner covers the code side: known-vulnerable dependencies, hardcoded secrets (including OpenAI, Anthropic and Hugging Face keys), static analysis and infrastructure-as-code misconfiguration. It also has AI-specific rules that line up with the OWASP Top 10 for LLM Applications 2025. It flags user input inserted into a system prompt (LLM01, LLM07), LLM output passed to code execution (LLM05), agent tools that can run shell commands (LLM06), an AI provider key exposed to the browser (LLM02, LLM10), and models loaded with trust_remote_code=True or unsafe torch.load calls (LLM03).
Where Scanverra does not reach
Scanverra does not actively attack your application. It does not fuzz parameters for SQL injection, log in as two users to test access control, or try to jailbreak your chatbot with prompt injection payloads. For active DAST testing, a tool like OWASP ZAP is the better fit (see Scanverra vs OWASP ZAP). Insecure Design, Logging and Alerting Failures, Misinformation and most of Mishandling of Exceptional Conditions need design review and manual testing. No scanner can honestly claim to cover them.
A practical OWASP Top 10 checklist for 2025
- Update policies, tickets and report templates from OWASP Top 10 2021 IDs to OWASP Top 10 2025 IDs, using the mapping table above.
- Run an external scan and fix misconfiguration first. It is now the number two OWASP Top 10 risk and the cheapest to fix.
- Scan dependencies and secrets on every pull request, then extend the review to CI/CD permissions and build integrity for A03:2025. Start with fixing outdated dependencies and removing hardcoded secrets.
- Write access-control tests for every endpoint that takes an object ID.
- Review error handling for fail-open logic and leaky error pages (A10:2025).
- Make sure security events trigger alerts someone actually reads (A09:2025).
- If you ship an LLM feature, threat-model it against the official OWASP Top 10 for LLM Applications 2025: limit agent permissions, treat model output as untrusted input, keep secrets out of prompts, and cap tokens and spend.
- Rank what you find by real severity. Our guide to CVSS scores helps you decide what to fix first.
The OWASP Top 10 changes every few years, but the habit it encourages does not: know which categories apply to your stack, test each one with the right method, and keep evidence. A free security scan is a quick first pass on the externally visible part of the OWASP Top 10 2025.
Preguntas frecuentes
The OWASP Top 10 2025 is the current official edition, published at top10.owasp.org. It replaced the OWASP Top 10 2021. Broken Access Control stays at number one, Security Misconfiguration rises to second, Software Supply Chain Failures enters at third, and Mishandling of Exceptional Conditions is a new category at A10.
Server-Side Request Forgery was merged into Broken Access Control, Vulnerable and Outdated Components was widened into Software Supply Chain Failures, Security Misconfiguration moved from fifth to second, Cryptographic Failures, Injection and Insecure Design each dropped two places, and Mishandling of Exceptional Conditions was added as A10:2025. Authentication and Logging categories were also renamed.
It is a separate list from the OWASP Gen AI Security Project, released in November 2024: Prompt Injection, Sensitive Information Disclosure, Supply Chain, Data and Model Poisoning, Improper Output Handling, Excessive Agency, System Prompt Leakage, Vector and Embedding Weaknesses, Misinformation, and Unbounded Consumption. The official version is published at genai.owasp.org.
For the 2025 edition there is no separately named technical details document. The technical detail for each risk (description, examples, prevention, attack scenarios and references) is in the official OWASP Top 10 for LLM Applications 2025 PDF and the per-risk pages on genai.owasp.org.
No. Automated scanning reliably finds misconfiguration, cryptographic issues, vulnerable components and exposed secrets, but categories such as Broken Access Control, Insecure Design and Logging and Alerting Failures need active testing and manual review. Scanverra's passive security scan and repository scanner cover the externally visible and code-level parts, not active exploitation.
Related reading
Understanding the OWASP Top 10 for Website Owners (Not Just Developers)
The industry's most-cited security list, translated out of developer jargon - what each category actually means for a site you own but didn't build yourself.
Scanverra vs. OWASP ZAP
A free, open-source DAST (dynamic application security testing) proxy for actively probing a running web app for vulnerabilities - no hosted dashboard, no pricing.
How to Fix Missing Security Headers
Why missing or weak HTTP security headers leave otherwise-secure code exposed, and how to configure HSTS, CSP, and the rest correctly.
Software Composition Analysis: A Complete Guide to Dependency Scanning
What SCA tools actually check, how a CVE in a transitive dependency you've never heard of still becomes your problem, and how to build a workable remediation process.
How to Fix Hardcoded Secrets in Your Codebase
An API key committed to a public (or even private) repo is compromised the moment it's pushed - how Scanverra's repo scanner finds them, and how to rotate and remove them properly.
Free Security Scan
Check a live site for OWASP Top 10 misconfiguration and crypto issues
Repository Scanner
Dependencies, secrets and AI/LLM security rules in your code
Find out which headers you're missing
Run a free security scan and get a plain-English breakdown of every header, cert, and exposed secret.
Run a free security scan