# OWASP Top 10

> The long-standing community list of the most critical web application security risks, revised every few years.

It is the common vocabulary of web security: broken access control, cryptographic failures, injection, insecure design, misconfiguration and the rest. Its value is less the ranking than the shared language — it lets a developer, a tester and a client describe the same problem without three different names for it.

It is a floor, not a ceiling. Covering all ten means the obvious ways in are closed, which is genuinely worth doing and is not the same as being secure; the interesting findings in most engagements are business-logic flaws that no generic list can anticipate because they depend on what the application is for.

## Related terms

- https://dfieldsolutions.com/en/glossary/penetration-test.md
- https://dfieldsolutions.com/en/glossary/owasp-llm-top-10.md
- https://dfieldsolutions.com/en/glossary/security-audit.md

---

Source: https://dfieldsolutions.com/en/glossary/owasp-top-10
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
