OWASP Top 10
The OWASP Top 10 is the industry baseline for web application security risks — what to test, what to prioritise, and what auditors expect to see covered in every penetration testing engagement.
This page explains each OWASP Top 10 category and links to the exact TigerStrike scanners that validate it in your applications and APIs.
A01 — Broken Access Control
Access control failures remain the #1 web application risk. Users accessing functions or data outside their intended authorisation — IDOR, forced browsing, privilege escalation, missing object-level authorisation.
A02 — Cryptographic Failures
Weak cryptography, hard-coded secrets, missing TLS, broken signature verification, and improper key management. Previously 'Sensitive Data Exposure'.
A03 — Injection
SQL, NoSQL, LDAP, XPath, OS command, template, and expression language injection. Attacker-controlled data interpreted as code by a downstream parser.
A04 — Insecure Design
Design-level flaws that no amount of implementation hardening fixes — missing threat modelling, trust-boundary violations, insecure business logic.
A05 — Security Misconfiguration
Default credentials, directory listing enabled, debug mode in production, verbose error messages, open cloud buckets, missing security headers.
A06 — Vulnerable and Outdated Components
Known-vulnerable library versions, unmaintained dependencies, dependency confusion attacks. The 'library of CVEs' category.
A07 — Identification and Authentication Failures
Credential stuffing, weak password policy, missing MFA, session fixation, flawed authentication flows. Previously 'Broken Authentication'.
A08 — Software and Data Integrity Failures
Insecure deserialisation, unsigned update channels, CI/CD pipeline tampering, missing integrity verification on third-party data.
A09 — Security Logging and Monitoring Failures
Missing logging, insufficient alerting, log injection, missing audit trail — the category that keeps breaches invisible.
A10 — Server-Side Request Forgery (SSRF)
Server fetches attacker-controlled URL — exposing internal services, cloud metadata endpoints, and lateral movement surface. Elevated to top-10 in 2021 and still rising.
Frequently Asked Questions
What is the OWASP Top 10?
The OWASP Top 10 is a periodically-updated list from the Open Worldwide Application Security Project (OWASP) ranking the most critical security risks to web applications. It is the industry baseline that compliance auditors (SOC 2, ISO 27001, PCI DSS), customers in vendor security reviews, and most pen testing scopes reference as mandatory coverage.
What is new in the OWASP Top 10 2025 revision?
The 2025 revision reinforces Broken Access Control at #1 (unchanged since 2021), elevates software supply chain risks under A06 and A08, and adds specific guidance on API-first applications and modern authentication. SSRF remains at A10 as a rapidly-growing standalone risk class.
Is OWASP Top 10 testing enough for compliance?
OWASP Top 10 is a baseline, not a complete scope. SOC 2, ISO 27001, PCI DSS, and HIPAA all expect OWASP Top 10 coverage plus additional categories specific to the framework (business logic, infrastructure, APIs, cloud, authentication edges). TigerStrike covers OWASP Top 10 by default and extends to the framework-specific categories automatically.
How does TigerStrike pen testing differ from an OWASP ZAP scanner?
OWASP ZAP is a free DAST scanner that identifies OWASP Top 10 patterns in web applications. TigerStrike is an AI pen testing platform that uses 143+ specialised scanners, validates every finding with exploitation evidence, chains vulnerabilities into attack paths, and produces compliance-ready reports — the pen testing equivalent of DAST plus manual-grade exploitation at machine scale.
Stop finding vulnerabilities manually
TigerStrike uses AI agents to continuously discover, validate, and exploit vulnerabilities across your applications — so your team can focus on fixing what matters.