Latest alerts
  1. Home
  2. Insights
  3. AppSec
// appsec · 6 min read

OWASP Top 10:2025, explained for business leaders

Supply-chain failures and mishandled exceptions are new on the list. What each category means for your applications — in plain language.

Published 27 August 2026 · Dravincon Security Team

The OWASP Top 10 is the most widely used reference for web-application risk, and the 2025 edition reshuffles the list. Here is what each category means and the question to ask your team.

  1. A01 Broken Access Control — users doing things they should not, like viewing another customer's invoice by changing a number in the URL. Ask: is every request authorised on the server, not just hidden in the UI?
  2. A02 Security Misconfiguration — default passwords, open cloud storage, verbose errors. Climbed to #2. Ask: do we harden from a baseline and check for drift?
  3. A03 Software Supply Chain Failures — new and broader than "vulnerable components": compromised packages, build systems and updates. Ask: do we know every dependency we ship, and who can change our pipeline?
  4. A04 Cryptographic Failures — weak or missing encryption, leaked keys. Ask: is sensitive data encrypted in transit and at rest, and where are the keys?
  5. A05 Injection — SQL, command and other injection, including cross-site scripting. Ask: do we use parameterised queries and output encoding everywhere?
  6. A06 Insecure Design — flaws no amount of clean code can fix, such as a password reset that can be brute-forced. Ask: do we threat-model before building?
  7. A07 Authentication Failures — credential stuffing, weak session handling, missing MFA. Ask: do we rate-limit logins and support MFA or passkeys?
  8. A08 Software or Data Integrity Failures — trusting unsigned updates, unsafe deserialisation. Ask: do we verify what we load and execute?
  9. A09 Security Logging & Alerting Failures — breaches nobody notices. Ask: would we know today if an admin account was misused?
  10. A10 Mishandling of Exceptional Conditions — new: systems that fail open, leak data in errors or behave unpredictably under unusual input. Ask: when something breaks, does it fail safe?

What this means for testing

Scanners help with misconfiguration and some injection. Access control, insecure design, business logic and exception handling need a human tester who understands how your application is meant to work. That is why our VAPT is manual-first.

// ready when you are

Find out how an attacker sees you — before they do.

Book a free 30-minute scoping call with our security team. No sales script, just an honest view of your risk and what to do first.

Call Email Under attack? Free DPDP Check