The OWASP Top 10 is not a standard and was never meant to be one. It is an awareness document — a ranked list of the most important categories of web application risk, built from data contributed by testing firms and a community survey. But because nearly every customer questionnaire asks about it, it matters what it says.
What stayed the same
Broken access control is still number one, and server-side request forgery, which had its own entry in 2021, is now part of it. That is the right call: SSRF is fundamentally a server doing something on behalf of a user that the user should not be able to make it do.
Security misconfiguration rose to second place, which matches what we see. Modern applications are assembled from cloud services, each with its own settings, and the defaults are rarely the secure option.
What is new
Two additions stand out. Software supply chain failures broadens the old “vulnerable and outdated components” category to the whole chain — dependencies, build systems, package registries and the scripts your pages load from third parties. And mishandling of exceptional conditions covers what happens when things go wrong: errors that leak internals, failures that fail open, and states the developers never expected.
“The list moved from the code you wrote to everything your code depends on, and everything that happens when it breaks.”
What it means for an existing application
If your last test was mapped to the 2021 list, nothing about your application changed when the new edition was published. But the questions you will be asked did. Expect questionnaires to ask how you manage dependencies and third-party scripts, and how your application behaves under error conditions.
Practically, three things are worth doing now: generate and keep a software bill of materials for each application, inventory the third-party scripts on your most sensitive pages, and review how your error handling behaves — especially whether any authorisation check can be skipped when something upstream fails.
Use it as a floor, not a scope
The Top 10 is a good list of things that must be covered and a poor definition of a complete test. For that, OWASP’s Application Security Verification Standard — ASVS 5.0, released in 2025 — sets out testable requirements at three levels. A report that says “verified against ASVS Level 2” tells a reader far more than one that says “tested for the OWASP Top 10”.