Published 27 August 2026 · Dravincon Security Team
The OWASP Top 10 is the most widely used reference for web-application risk, and the 2025 edition reshuffles the list. Here is what each category means and the question to ask your team.
- A01 Broken Access Control — users doing things they should not, like viewing another customer's invoice by changing a number in the URL. Ask: is every request authorised on the server, not just hidden in the UI?
- A02 Security Misconfiguration — default passwords, open cloud storage, verbose errors. Climbed to #2. Ask: do we harden from a baseline and check for drift?
- A03 Software Supply Chain Failures — new and broader than "vulnerable components": compromised packages, build systems and updates. Ask: do we know every dependency we ship, and who can change our pipeline?
- A04 Cryptographic Failures — weak or missing encryption, leaked keys. Ask: is sensitive data encrypted in transit and at rest, and where are the keys?
- A05 Injection — SQL, command and other injection, including cross-site scripting. Ask: do we use parameterised queries and output encoding everywhere?
- A06 Insecure Design — flaws no amount of clean code can fix, such as a password reset that can be brute-forced. Ask: do we threat-model before building?
- A07 Authentication Failures — credential stuffing, weak session handling, missing MFA. Ask: do we rate-limit logins and support MFA or passkeys?
- A08 Software or Data Integrity Failures — trusting unsigned updates, unsafe deserialisation. Ask: do we verify what we load and execute?
- A09 Security Logging & Alerting Failures — breaches nobody notices. Ask: would we know today if an admin account was misused?
- A10 Mishandling of Exceptional Conditions — new: systems that fail open, leak data in errors or behave unpredictably under unusual input. Ask: when something breaks, does it fail safe?
What this means for testing
Scanners help with misconfiguration and some injection. Access control, insecure design, business logic and exception handling need a human tester who understands how your application is meant to work. That is why our VAPT is manual-first.