Owasp top 10
What is the OWASP Top 10? The **OWASP Top 10** is a standard "awareness document" published by the Open Worldwide Application Security Project (OWASP). It ranks the 10 most critical security risks facing web applications, based on real-world vulnerability data and industry consensus. It's the baseline reference for developers, pentesters, and auditors — and standards like PCI DSS and ISO 27001 reference it as a best-practice benchmark. The current edition is **OWASP Top 10:2025** (which replaced the 2021 edition) . Here's the list, what each risk means, and how to test for it. --- ## The 2025 list + how to test each one ### A01 — Broken Access Control Users can access data or functions beyond their permissions (IDOR, privilege escalation, force browsing). SSRF from the 2021 list is now folded into this category. **How to test:** - Create two accounts (user A, user B). Change IDs in URLs/requests (`/api/user/1001` → `1002`) and see if you can read/modify B's data w...