Skip to content
December 27, 2025

OWASP Top Ten 2025

The 2025 edition of the OWASP Top Ten is out. What moved, what is new, what it says about where web application risk is actually concentrating now.

Brackish Security1 min read

The OWASP Top Ten is one of the most influential security awareness documents in application security, published by the Open Worldwide Application Security Project (OWASP). It represents a community-driven ranking of the most critical risks facing web applications. The 2025 edition continues the tradition established by previous versions, such as the 2021 list, while updating its focus to reflect changes in how modern software is built, deployed, and attacked.

Here is the updated list:

  1. A01:2025 - Broken Access Control
  2. A02:2025 - Security Misconfiguration
  3. A03:2025 - Software Supply Chain Failures
  4. A04:2025 - Cryptographic Failures
  5. A05:2025 - Injection
  6. A06:2025 - Insecure Design
  7. A07:2025 - Authentication Failures
  8. A08:2025 - Software or Data Integrity Failures
  9. A09:2025 - Security Logging and Alerting Failures
  10. A10:2025 - Mishandling of Exceptional Conditions

From what it looks like, there are two new categories:

Beyond that, there are some additional changes and reorganizations, we recommend you check out the full new document on the OWASP site.

Want this tested against your environment?

Reading about an attack path is not the same as knowing whether yours holds. We can tell you which it is.

Scope an engagement