OWASP Top 10

Informational

OWASP Top 10

Definition

The OWASP Top 10 is a reference document published by the Open Web Application Security Project that lists the 10 most critical security-risk categories in web applications. It is updated periodically and is the de facto standard for web security assessment. The 2021 version includes: Broken Access Control, Cryptographic Failures, Injection, Insecure Design, Security Misconfiguration, and more.

Impact

Reference standard for security testing and auditsGuide for prioritizing vulnerabilities in bug bountyRequirement in regulatory compliance (PCI DSS, ISO 27001)Educational baseline for web security trainingFramework for application risk assessment

Examples

OWASP Top 10 - 2021

The 10 categories are: A01 Broken Access Control, A02 Cryptographic Failures, A03 Injection, A04 Insecure Design, A05 Security Misconfiguration, A06 Vulnerable and Outdated Components, A07 Identification and Authentication Failures, A08 Software and Data Integrity Failures, A09 Security Logging and Monitoring Failures, A10 Server-Side Request Forgery (SSRF).

External references

Practice OWASP Top 10 with real labs

Apply what you've learned in safe environments based on real bug bounty reports.

See practice labs
hunters training
712

hunters training

labs from real reports
55

labs from real reports

completions
1,206

completions

in bounties practiced
$213,970

in bounties practiced

46 flags captured this week·Real reports from HackerOne · Bugcrowd · Intigriti·No commitment·Free Academy
BBLabs · bug bounty training

Stop reading about bugs and start hunting them

Create your free account and practice on labs based on real reports that paid out thousands of euros. The Academy is free forever.

No card · free Academy · cancel anytime