Versioned taxonomy

OWASP API Security Top 10:2023

The current stable OWASP API Security Top 10 edition.

Stable IDowasp:owasp:api:security:top:10:2023Last updatedLast verifiedLegacy review pendingProvenanceOWASP primary source
API1

Broken Object Level Authorization

API2

Broken Authentication

API3

Broken Object Property Level Authorization

API4

Unrestricted Resource Consumption

API5

Broken Function Level Authorization

API6

Unrestricted Access to Sensitive Business Flows

API7

Server Side Request Forgery

API8

Security Misconfiguration

API9

Improper Inventory Management

API10

Unsafe Consumption of APIs

Primary source and edition policy

Vulns.co preserves older editions at stable URLs and does not silently rewrite historical mappings.

Open the official OWASP edition ↗