{"id":17584,"date":"2016-04-11T09:13:18","date_gmt":"2016-04-11T09:13:18","guid":{"rendered":"https:\/\/www.checkmarx.com\/?p=17584"},"modified":"2025-11-18T17:53:35","modified_gmt":"2025-11-18T15:53:35","slug":"owaspowasp-top-10","status":"publish","type":"post","link":"https:\/\/checkmarx.com\/chapter-six\/owaspowasp-top-10\/","title":{"rendered":"OWASP\/OWASP TOP 10"},"content":{"rendered":"<p>The Open Web Application Security Project\u00a0(OWASP) is an open-source appsec\u00a0community. Its goal is to increase application security\u00a0awareness. OWASP is\u00a0the source\u00a0behind\u00a0the industry standard OWASP Top 10.<br>\nMore and more companies from various industrial sectors are embracing this vulnerability list, which consistently encompasses today&#8217;s most critical security flaws. OWASP Top 10 2013 and <a href=\"https:\/\/www.owasp.org\/index.php\/Projects\/OWASP_Mobile_Security_Project_-_Top_Ten_Mobile_Risks\" target=\"_blank\" rel=\"noopener\">OWASP Mobile Top 10 2014<\/a> are created and updated by AppSec experts from around the world, something that has helped create a unique AppSec community.<br>\nBesides offering the aforementioned cross-sector reference lists that help organizations secure their applications, OWASP is also widely acknowledged for its other contributions around the world (conferences, hackathons, lectures and more) to the field of application security. It even won the <a href=\"https:\/\/media.scmagazine.com\/documents\/64\/botn2014sm_15794.pdf\" target=\"_blank\" rel=\"noopener\">SC Magazine Editor&#8217;s Choice Award<\/a> in 2014.<\/p>\n<p><strong>Additional Reading:<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/www.owasp.org\/index.php\/Top_10_2013-Top_10\" target=\"_blank\" rel=\"noopener\">The Open Web Application Security Project (OWASP\/OWASP TOP 10)<\/a><\/li>\n<li><a href=\"https:\/\/checkmarx.com\/glossary\/owasp-top-10\/\" target=\"_blank\" rel=\"noopener\">OWASP TOP 10 Vulnerabilities at Checkmarx application security Glossary<\/a><\/li>\n<\/ul>\n<p><strong>Continue to\u00a0<a href=\"\/chapter-six\/sans-25\/\" target=\"_blank\" rel=\"noopener\">AppSec Standards &amp; Benchmarks: SANS 25<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Open Web Application Security Project\u00a0(OWASP) is an open-source appsec\u00a0community. Its goal is to increase application security\u00a0awareness. OWASP is\u00a0the source\u00a0behind\u00a0the industry standard OWASP Top 10. More and more companies from various industrial sectors are embracing this vulnerability list, which consistently encompasses today&#8217;s most critical security flaws. OWASP Top 10 2013 and OWASP Mobile Top 10 [&hellip;]<\/p>\n","protected":false},"author":98,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[84],"tags":[],"class_list":["post-17584","post","type-post","status-publish","format-standard","hentry","category-blog"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>OWASP\/OWASP TOP 10<\/title>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"OWASP\/OWASP TOP 10\" \/>\n<meta property=\"og:description\" content=\"The Open Web Application Security Project\u00a0(OWASP) is an open-source appsec\u00a0community. Its goal is to increase application security\u00a0awareness. OWASP is\u00a0the source\u00a0behind\u00a0the industry standard OWASP Top 10. More and more companies from various industrial sectors are embracing this vulnerability list, which consistently encompasses today&#8217;s most critical security flaws. OWASP Top 10 2013 and OWASP Mobile Top 10 [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/chapter-six\/owaspowasp-top-10\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:published_time\" content=\"2016-04-11T09:13:18+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-18T15:53:35+00:00\" \/>\n<meta name=\"author\" content=\"Dina Shkolnik\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Dina Shkolnik\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/checkmarx.com\/chapter-six\/owaspowasp-top-10\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/chapter-six\/owaspowasp-top-10\/\"},\"author\":{\"name\":\"Dina Shkolnik\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/3977ad091ce6bab5124df61bcd96018e\"},\"headline\":\"OWASP\/OWASP TOP 10\",\"datePublished\":\"2016-04-11T09:13:18+00:00\",\"dateModified\":\"2025-11-18T15:53:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/chapter-six\/owaspowasp-top-10\/\"},\"wordCount\":154,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"articleSection\":[\"Blog\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/checkmarx.com\/chapter-six\/owaspowasp-top-10\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/chapter-six\/owaspowasp-top-10\/\",\"url\":\"https:\/\/checkmarx.com\/chapter-six\/owaspowasp-top-10\/\",\"name\":\"OWASP\/OWASP TOP 10\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"datePublished\":\"2016-04-11T09:13:18+00:00\",\"dateModified\":\"2025-11-18T15:53:35+00:00\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/chapter-six\/owaspowasp-top-10\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/3977ad091ce6bab5124df61bcd96018e\",\"name\":\"Dina Shkolnik\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/89235c218444ceedcdaab005794a30a543e682b53c6d857767f7c3a91a9a2597?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/89235c218444ceedcdaab005794a30a543e682b53c6d857767f7c3a91a9a2597?s=96&d=mm&r=g\",\"caption\":\"Dina Shkolnik\"},\"url\":\"https:\/\/checkmarx.com\/author\/dina\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"OWASP\/OWASP TOP 10","robots":{"index":"noindex","follow":"follow"},"og_locale":"en_US","og_type":"article","og_title":"OWASP\/OWASP TOP 10","og_description":"The Open Web Application Security Project\u00a0(OWASP) is an open-source appsec\u00a0community. Its goal is to increase application security\u00a0awareness. OWASP is\u00a0the source\u00a0behind\u00a0the industry standard OWASP Top 10. More and more companies from various industrial sectors are embracing this vulnerability list, which consistently encompasses today&#8217;s most critical security flaws. OWASP Top 10 2013 and OWASP Mobile Top 10 [&hellip;]","og_url":"https:\/\/checkmarx.com\/chapter-six\/owaspowasp-top-10\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_published_time":"2016-04-11T09:13:18+00:00","article_modified_time":"2025-11-18T15:53:35+00:00","author":"Dina Shkolnik","twitter_card":"summary_large_image","twitter_creator":"@checkmarx","twitter_site":"@checkmarx","twitter_misc":{"Written by":"Dina Shkolnik","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/checkmarx.com\/chapter-six\/owaspowasp-top-10\/#article","isPartOf":{"@id":"https:\/\/checkmarx.com\/chapter-six\/owaspowasp-top-10\/"},"author":{"name":"Dina Shkolnik","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/3977ad091ce6bab5124df61bcd96018e"},"headline":"OWASP\/OWASP TOP 10","datePublished":"2016-04-11T09:13:18+00:00","dateModified":"2025-11-18T15:53:35+00:00","mainEntityOfPage":{"@id":"https:\/\/checkmarx.com\/chapter-six\/owaspowasp-top-10\/"},"wordCount":154,"commentCount":0,"publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"articleSection":["Blog"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/checkmarx.com\/chapter-six\/owaspowasp-top-10\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/chapter-six\/owaspowasp-top-10\/","url":"https:\/\/checkmarx.com\/chapter-six\/owaspowasp-top-10\/","name":"OWASP\/OWASP TOP 10","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"datePublished":"2016-04-11T09:13:18+00:00","dateModified":"2025-11-18T15:53:35+00:00","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/chapter-six\/owaspowasp-top-10\/"]}]},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]},{"@type":"Person","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/3977ad091ce6bab5124df61bcd96018e","name":"Dina Shkolnik","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/89235c218444ceedcdaab005794a30a543e682b53c6d857767f7c3a91a9a2597?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/89235c218444ceedcdaab005794a30a543e682b53c6d857767f7c3a91a9a2597?s=96&d=mm&r=g","caption":"Dina Shkolnik"},"url":"https:\/\/checkmarx.com\/author\/dina\/"}]}},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/17584","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/98"}],"replies":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/comments?post=17584"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/17584\/revisions"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=17584"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/categories?post=17584"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/tags?post=17584"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}