← ALL FRAMEWORKS

OWASP Top 10

Information Security

Issued by OWASP Foundation

The OWASP Top 10 is a standard awareness document for developers and application security teams, representing a broad consensus on the most critical security risks to web applications. It is published by the OWASP Foundation and revised periodically from contributed vulnerability data plus a community survey; the current release is the OWASP Top 10:2025, succeeding the 2021 edition. Although it is not a certifiable standard and carries no audit regime of its own, it is referenced directly by other frameworks — PCI DSS requires developer training covering the Top 10 risks, and it is widely used as the baseline for secure-coding policies, application penetration test scoping, and vendor security questionnaires.

Get notified the moment OWASP Top 10 actually changes — reviewed by a human before it ever reaches you.

Get started free

Most recent update

No published updates yet

This framework hasn't had a confirmed update yet — check back after the next monitoring run.