Which organization publishes the OWASP Top 10 list of major web-application security risks?

The story behind the answer

The OWASP Foundation publishes the OWASP Top 10 list of major web-application security risks.

OWASP stands for the Open Worldwide Application Security Project, a nonprofit community focused on improving software security. Its Top 10 project summarizes widely observed and important risks in web applications, helping developers, testers, educators, and security teams prioritize defensive work.

The list is not a law or a complete catalog of every vulnerability. It is a risk-awareness document that groups related weaknesses, such as broken access control, cryptographic failures, injection, and insecure design. The categories and ordering can change as application technology and attack patterns evolve.

A common mix-up is treating OWASP as a commercial scanning product or a government agency. The OWASP Foundation supports community projects, chapters, conferences, documentation, and open tools. Its materials are widely used in secure-development training, but organizations still need threat modeling and testing suited to their own systems.

Source: Wikipedia · fact-checked Sept. 2026

Add question to a list

Choose a list to keep this question in: