

A03:2021-Injection slides down to the third position.This category often leads to sensitive data exposure or system compromise. The renewed name focuses on failures related to cryptography as it has been implicitly before. A02:2021-Cryptographic Failures shifts up one position to #2, previously known as A3:2017-Sensitive Data Exposure, which was broad symptom rather than a root cause.The 34 CWEs mapped to Broken Access Control had more occurrences in applications than any other category. A01:2021-Broken Access Control moves up from the fifth position to the category with the most serious web application security risk the contributed data indicates that on average, 3.81% of applications tested had one or more Common Weakness Enumerations (CWEs) with more than 318k occurrences of CWEs in this risk category.

We've changed names when necessary to focus on the root cause over the symptom.

There are three new categories, four categories with naming and scoping changes, and some consolidation in the Top. Without you, this installment would not happen. Welcome to the latest installment of the OWASP Top 10! The OWASP is all-new, with a new graphic design and an available one-page infographic you can print or obtain from our home page.Ī huge thank you to everyone that contributed their time and data for this iteration. Introduction Welcome to the OWASP Top 10 - 2021
