Versioned taxonomy
OWASP API Security Top 10:2023
The current stable OWASP API Security Top 10 edition.
Broken Authentication
Broken Object Property Level Authorization
Unrestricted Resource Consumption
Broken Function Level Authorization
Unrestricted Access to Sensitive Business Flows
Server Side Request Forgery
Security Misconfiguration
Improper Inventory Management
Unsafe Consumption of APIs
Primary source and edition policy
Vulns.co preserves older editions at stable URLs and does not silently rewrite historical mappings.
Open the official OWASP edition ↗