OWASP Top 10 2025 Released: Major Revisions and Two New Security Classes Added
The Open Web Application Security Project (OWASP) has officially unveiled the eighth edition of its influential Top 10 security risks list for 2025, introducing significant changes that reflect the evolving landscape of application security threats.The…
The Open Web Application Security Project (OWASP) has officially unveiled the eighth edition of its influential Top 10 security risks list for 2025, introducing significant changes that reflect the evolving landscape of application security threats.The update features two new security categories and substantial shifts in risk rankings based on contributed data and community feedback.Significant Additions to the ListThe 2025 edition introduces Software Supply Chain Failures as a critical new category at position A03.RankCategoryCWEsPrevalenceA01Broken Access Control403.73%A02Security Misconfiguration163.00%A03Software Supply Chain Failures5LowA04Cryptographic Failures323.80%A05Injection38HighA06Insecure Design36ModerateA07Authentication Failures36ModerateA08Software or Data Integrity Failures5ModerateA09Logging & Alerting Failures5ModerateA10Mishandling of Exceptional Conditions24NewThis represents an expanded focus from the previous “Vulnerable and Outdated Components” category, now encompassing broader compromises occurring across the entire software dependency ecosystem, build systems, and distribution infrastructure.This addition reflects growing concerns about supply chain attacks that have dominated security headlines in recent years.OWASP Top 10 2025 ReleasedThe second newcomer is Mishandling of Exceptional Conditions at position A10. This entirely new category addresses 24 Common Weakness Enumerations (CWEs), focusing on improper error handling, logical errors, and failing open scenarios that systems encounter under abnormal conditions.Broken Access Control maintains its dominant position at number one, with data indicating that 3.73% of tested applications contained at least one of the 40 CWEs in this category.The most dramatic change sees Security Misconfiguration surge from fifth place in 2021 to second position in 2025, affecting 3.00% of applications tested across 16 CWEs.Meanwhile, previously high-ranking threats have fallen. Cryptographic Failures dropped from second to fourth place, Injection vulnerabilities slid from third to fifth, and Insecure Design moved from fourth to sixth position. Despite these declines, these categories remain critical security concerns.The 2025 list analyzed 589 CWEs across 248 categories, a substantial increase from approximately 400 CWEs in 2021.OWASP combined data-driven analysis with community input, using eight data-informed categories and two community-voted categories to address emerging threats that testing may not yet reliably detect.The project analyzed roughly 175,000 CVE records mapped to CWEs from the National Vulnerability Database, incorporating CVSS exploit and impact scores to assess risk severity.This comprehensive approach ensures the list captures both established threats visible in testing data and emerging risks identified by security practitioners.The updated OWASP Top 10 2025 serves as a crucial awareness document for developers, security teams, and organizations worldwide.With increased emphasis on supply chain security and proper error handling, the list addresses modern attack vectors while maintaining focus on persistent threats such as access control failures and misconfigurations that continue to plague applications.Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.
Based on reporting by GBHackers.
