The OWASP Top Ten
Welcome to the OWASP Top Ten supplemental site.
This is where you can learn about how the Top Ten is built.
This site is managed by the Top Ten core team in conjunction with the OWASP project site and GitHub repository.
The OWASP Top Ten is a standard awareness document for developers and web application security. It represents a broad consensus about the most critical security risks to web applications. It was started in 2003 to help organizations and developer with a starting point for secure development. Over the years it's grown into a pseudo standard that is used as a baseline for compliance, education, and vendor tools.
Current project status as of Sept 2025
We are planning to announce the release of the OWASP Top 10:2025 at the OWASP Global AppSec Conf in DC the first week of Nov 2025.
https://owasp.org/Top10
The OWASP Top Ten Community Survey is active, please provide your input!
https://forms.gle/jL3r5Xgg1Hj2bv2B9
Data Collection (Now - Nov 2025)
Community Survey (Open)
Data Normalization (Complete)
Review Process (In-progress)
Documentation Updates (In-progress)
International Translations
The latest information and call for action





