← Back to Glossary
cybersecurityintermediate

OWASP (OWASP)

OWASP (Open Worldwide Application Security Project) is a nonprofit that publishes community-developed web application security standards, most notably the OWASP Top 10 risk list.

OWASP (Open Worldwide Application Security Project) is a nonprofit foundation that publishes open, community-developed standards for web application security, most notably the OWASP Top 10 — a periodically updated list of the most critical application security risks based on large-scale vulnerability data and industry practitioner input.

How It Works

OWASP's Top 10 is built from analysis of vulnerability data (CVEs) contributed by security vendors and testing firms, combined with a structured survey of security practitioners, then ranked by incidence rate, exploitability, and impact. The list isn't a complete security framework on its own — it's an awareness document meant to focus development and security teams on the highest-leverage risks first, and it's widely used as a baseline for security audits, vendor questionnaires, and procurement requirements.

OWASP Top 10 2021 vs. 2025
Rank20212025
#1Broken Access ControlBroken Access Control (expanded scope)
#2Cryptographic FailuresSecurity Misconfiguration (up from #5)
#3InjectionSoftware Supply Chain Failures (new)
NewMishandling of Exceptional Conditions

Dbugger Enterprise Context

Dbugger builds enterprise applications against current OWASP guidance by default — Next.js, React, Python, and PostgreSQL stacks with access control and configuration reviewed at architecture time, not only before launch.

Frequently asked questions

Need help applying this?

Our team works with enterprise stacks across WordPress, APIs, Claude AI, and CRM every day. Tell us what you're building.

Talk to us
OWASP