OWASP Top 10 (Web) (2025)
The 10 categories in the OWASP Top 10 (Web) (2025), each mapped to CWE weaknesses and how TurboPentest tests for it.
- A01:2025Broken Access Control
Access-control failures including IDOR, missing authorization, JWT/SAML weaknesses. Maintains the #1 position from 2021. Server-Side Request Forgery (SSRF) was rolled into this category in 2025.
- A02:2025Security Misconfiguration
Insecure defaults, missing hardening, exposed admin/debug interfaces, misconfigured cloud services. Moved up from #5 in 2021 to #2 in 2025.
- A03:2025Software Supply Chain Failures
Expansion of A06:2021 (Vulnerable and Outdated Components) to cover compromises across the entire ecosystem of software dependencies, build systems, and distribution infrastructure.
- A04:2025Cryptographic Failures
Weak crypto, missing crypto, plaintext sensitive data, weak key management.
- A05:2025Injection
SQL injection, command injection, LDAP injection, NoSQL injection, XSS (reflected/stored/DOM), template injection. XSS is included as injection.
- A06:2025Insecure Design
Lack of threat modeling, missing security requirements, fundamentally insecure architecture.
- A07:2025Identification and Authentication Failures
Weak authentication, broken session management, credential stuffing tolerance, MFA bypass.
- A08:2025Software and Data Integrity Failures
Insecure deserialization, unsigned updates, untrusted CI/CD pipelines, integrity check failures.
- A09:2025Security Logging and Monitoring Failures
Inadequate logging, missing alerting, no audit trail, log-injection vulnerabilities.
- A10:2025Mishandling of Exceptional Conditions
New in 2025. Poor error and exception handling that leads to unpredictable or insecure behavior. Replaces SSRF as a standalone category, which moved into A01.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest