# The Categories — OWASP Top 10

Source: https://www.skillbyai.com/en/owasp-top-10/i-list

> 2021 list and the 2025 update.

## Ten categories of risk

The **2021** edition, widely referenced in training and audits, lists: A01 Broken Access Control, A02 Cryptographic Failures, A03 Injection (now including cross-site scripting), A04 Insecure Design, A05 Security Misconfiguration, A06 Vulnerable and Outdated Components, A07 Identification and Authentication Failures, A08 Software and Data Integrity Failures, A09 Security Logging and Monitoring Failures, and A10 Server-Side Request Forgery. The **2025** edition reorganises the list, notably adding software supply chain failures and the mishandling of exceptional conditions; check owasp.org for the current version. This course covers the risks behind both editions.

## OWASP Top 10:2021 at a glance

Category and one typical example each.

```text
A01 Broken Access Control              user changes /invoices/1001 to /invoices/1002 and sees another invoice
A02 Cryptographic Failures             passwords stored with unsalted MD5; site served over plain HTTP
A03 Injection                          SQL built by string concatenation; unescaped HTML output (XSS)
A04 Insecure Design                    no rate limit on password reset codes
A05 Security Misconfiguration          debug mode on in production; default admin credentials
A06 Vulnerable and Outdated Components old library with a known critical CVE
A07 Identification and Auth Failures   no protection against credential stuffing; weak sessions
A08 Software and Data Integrity        unsigned updates; compromised CI pipeline; unsafe deserialisation
A09 Security Logging and Monitoring    attacks go unnoticed for months
A10 Server-Side Request Forgery        server fetches attacker-supplied URL to internal metadata service
```

## Map findings to categories

Tagging bugs and pentest findings with Top 10 categories shows where your organisation is weakest.

**Quiz:** Which category was ranked first in the 2021 edition?

- [x] Broken Access Control
- [ ] Injection
- [ ] Cryptographic Failures
- [ ] Server-Side Request Forgery

*Answer:* Broken Access Control. Access control problems were the most common in the data.
