Lesson 2 / 25
The Categories
2021 list and the 2025 update.
Ten categories of risk
The 2021 edition, widely referenced in training and audits, lists: A01 Broken Access Control, A02 Cryptographic Failures, A03 Injection (now including cross-site scripting), A04 Insecure Design, A05 Security Misconfiguration, A06 Vulnerable and Outdated Components, A07 Identification and Authentication Failures, A08 Software and Data Integrity Failures, A09 Security Logging and Monitoring Failures, and A10 Server-Side Request Forgery. The 2025 edition reorganises the list, notably adding software supply chain failures and the mishandling of exceptional conditions; check owasp.org for the current version. This course covers the risks behind both editions.
OWASP Top 10:2021 at a glance
Category and one typical example each.
A01 Broken Access Control user changes /invoices/1001 to /invoices/1002 and sees another invoice
A02 Cryptographic Failures passwords stored with unsalted MD5; site served over plain HTTP
A03 Injection SQL built by string concatenation; unescaped HTML output (XSS)
A04 Insecure Design no rate limit on password reset codes
A05 Security Misconfiguration debug mode on in production; default admin credentials
A06 Vulnerable and Outdated Components old library with a known critical CVE
A07 Identification and Auth Failures no protection against credential stuffing; weak sessions
A08 Software and Data Integrity unsigned updates; compromised CI pipeline; unsafe deserialisation
A09 Security Logging and Monitoring attacks go unnoticed for months
A10 Server-Side Request Forgery server fetches attacker-supplied URL to internal metadata serviceMap findings to categories
Tagging bugs and pentest findings with Top 10 categories shows where your organisation is weakest.
Quick check: Which category was ranked first in the 2021 edition?
- Broken Access Control
- Injection
- Cryptographic Failures
- Server-Side Request Forgery
Answer
Broken Access Control — Access control problems were the most common in the data.