OWASP Top 10 Testing

OWASP Top 10

The OWASP Top 10 is the industry baseline for web application security risks — what to test, what to prioritise, and what auditors expect to see covered in every penetration testing engagement.

This page explains each OWASP Top 10 category and links to the exact TigerStrike scanners that validate it in your applications and APIs.

A01

A01 — Broken Access Control

Access control failures remain the #1 web application risk. Users accessing functions or data outside their intended authorisation — IDOR, forced browsing, privilege escalation, missing object-level authorisation.

Related TigerStrike scanners:
A02

A02 — Cryptographic Failures

Weak cryptography, hard-coded secrets, missing TLS, broken signature verification, and improper key management. Previously 'Sensitive Data Exposure'.

Related TigerStrike scanners:
A03

A03 — Injection

SQL, NoSQL, LDAP, XPath, OS command, template, and expression language injection. Attacker-controlled data interpreted as code by a downstream parser.

Related TigerStrike scanners:
A04

A04 — Insecure Design

Design-level flaws that no amount of implementation hardening fixes — missing threat modelling, trust-boundary violations, insecure business logic.

Related TigerStrike scanners:
A05

A05 — Security Misconfiguration

Default credentials, directory listing enabled, debug mode in production, verbose error messages, open cloud buckets, missing security headers.

Related TigerStrike scanners:
A06

A06 — Vulnerable and Outdated Components

Known-vulnerable library versions, unmaintained dependencies, dependency confusion attacks. The 'library of CVEs' category.

Related TigerStrike scanners:
A07

A07 — Identification and Authentication Failures

Credential stuffing, weak password policy, missing MFA, session fixation, flawed authentication flows. Previously 'Broken Authentication'.

Related TigerStrike scanners:
A08

A08 — Software and Data Integrity Failures

Insecure deserialisation, unsigned update channels, CI/CD pipeline tampering, missing integrity verification on third-party data.

Related TigerStrike scanners:
A09

A09 — Security Logging and Monitoring Failures

Missing logging, insufficient alerting, log injection, missing audit trail — the category that keeps breaches invisible.

Related TigerStrike scanners:
A10

A10 — Server-Side Request Forgery (SSRF)

Server fetches attacker-controlled URL — exposing internal services, cloud metadata endpoints, and lateral movement surface. Elevated to top-10 in 2021 and still rising.

Related TigerStrike scanners:

Frequently Asked Questions

What is the OWASP Top 10?

The OWASP Top 10 is a periodically-updated list from the Open Worldwide Application Security Project (OWASP) ranking the most critical security risks to web applications. It is the industry baseline that compliance auditors (SOC 2, ISO 27001, PCI DSS), customers in vendor security reviews, and most pen testing scopes reference as mandatory coverage.

What is new in the OWASP Top 10 2025 revision?

The 2025 revision reinforces Broken Access Control at #1 (unchanged since 2021), elevates software supply chain risks under A06 and A08, and adds specific guidance on API-first applications and modern authentication. SSRF remains at A10 as a rapidly-growing standalone risk class.

Is OWASP Top 10 testing enough for compliance?

OWASP Top 10 is a baseline, not a complete scope. SOC 2, ISO 27001, PCI DSS, and HIPAA all expect OWASP Top 10 coverage plus additional categories specific to the framework (business logic, infrastructure, APIs, cloud, authentication edges). TigerStrike covers OWASP Top 10 by default and extends to the framework-specific categories automatically.

How does TigerStrike pen testing differ from an OWASP ZAP scanner?

OWASP ZAP is a free DAST scanner that identifies OWASP Top 10 patterns in web applications. TigerStrike is an AI pen testing platform that uses 143+ specialised scanners, validates every finding with exploitation evidence, chains vulnerabilities into attack paths, and produces compliance-ready reports — the pen testing equivalent of DAST plus manual-grade exploitation at machine scale.

Stop finding vulnerabilities manually

TigerStrike uses AI agents to continuously discover, validate, and exploit vulnerabilities across your applications — so your team can focus on fixing what matters.