The OWASP Top 10:2025 is the latest edition of the industry-standard list of the most critical web application security risks. Here’s the full list, in order.
- A01 — Broken Access Control — the most serious risk again, including SSRF
- A02 — Security Misconfiguration — up from #5 in 2021
- A03 — Software Supply Chain Failures — expanded to cover the whole ecosystem
- A04 — Cryptographic Failures — down from #2
- A05 — Injection — down two spots from #3
- A06 — Insecure Design — down from #4
- A07 — Authentication Failures — holds steady at #7
- A08 — Software or Data Integrity Failures — holds steady at #8
- A09 — Security Logging & Alerting Failures — holds steady at #9
- A10 — Mishandling of Exceptional Conditions — new for 2025
Want to practice each one hands-on? Try our interactive OWASP Top 10:2025 labs.


