Versioned taxonomy

OWASP Web Top 10:2025

The current OWASP web application security taxonomy, preserved as a distinct edition.

Stable IDowasp:owasp:web:top:10:2025Last updatedLast verifiedLegacy review pendingProvenanceOWASP primary source
A01

Broken Access Control

Access control failures, including object-level authorization gaps and SSRF, allow actions outside intended permissions.

A02

Security Misconfiguration

Insecure defaults, unnecessary features, inconsistent hardening, and configuration drift expose systems.

A03

Software Supply Chain Failures

Compromise or weakness across dependencies, build systems, distribution, and update channels.

A04

Cryptographic Failures

Weak, missing, or incorrectly applied cryptography exposes sensitive data and trust boundaries.

A05

Injection

Untrusted data is interpreted as code, queries, commands, expressions, or browser content.

A06

Insecure Design

Missing or ineffective security controls originate in architecture, threat modeling, and business rules.

A07

Authentication Failures

Identity proofing, credential, session, and account-recovery weaknesses enable impersonation.

A08

Software or Data Integrity Failures

Software, updates, serialized data, and other artifacts cross trust boundaries without integrity verification.

A09

Security Logging & Alerting Failures

Insufficient logging, monitoring, and alerting delays detection and response.

A10

Mishandling of Exceptional Conditions

Fail-open behavior, improper error handling, and unexpected states undermine security controls.

Primary source and edition policy

Vulns.co preserves older editions at stable URLs and does not silently rewrite historical mappings.

Open the official OWASP edition ↗