Web Application Security: OWASP Top 10 in 2025

Discover the 2025 OWASP Top 10 vulnerabilities with practical code examples and mitigation strategies to secure your web applications.

Web Application Security: OWASP Top 10 in 2025

Is your company ready for AI? Download our free checklist →

Download checklist

Introduction

Web application security remains a moving target. As developers adopt new frameworks and deployment models, attackers evolve their techniques. The OWASP Top 10 is a community-driven list of the most critical security risks, updated periodically to reflect real-world threats. In 2025, the list includes both familiar challenges and emerging vectors.

This post explores each risk in detail, provides concrete code examples, and offers actionable mitigations. Whether you are a developer, architect, or security engineer, understanding these risks is essential to building resilient applications.

OWASP Top 10 Risks for 2025

1. Broken Access Control

Broken access control allows attackers to bypass authorization and perform actions as privileged users.

Example Vulnerability:

// Insecure: User-supplied ID used without verification
app.get('/api/user/:id', (req, res) => {
  const user = db.findUser(req.params.id);
  res.json(user);
});

Mitigation:

  • Use role-based access control (RBAC) at the function level.
  • Deny by default; explicitly allow only necessary permissions.
  • Validate every request against the authenticated user's privileges.

Secure Code:

app.get('/api/user/:id', (req, res) => {
  if (req.user.role !== 'admin' && req.user.id !== req.params.id) {
    return res.status(403).send('Forbidden');
  }
  const user = db.findUser(req.params.id);
  res.json(user);
});

2. Cryptographic Failures

This includes weak encryption, default ciphers, and improper certificate validation.

Example Vulnerability:

# Using MD5 for password hashing
import hashlib
hashed_password = hashlib.md5(password.encode()).hexdigest()

Mitigation:

  • Use bcrypt, Argon2, or PBKDF2 for password storage.
  • Always enforce HTTPS; use HSTS headers.
  • Avoid custom crypto; rely on well-vetted libraries.

Secure Code:

import bcrypt
hashed_password = bcrypt.hashpw(password.encode(), bcrypt.gensalt())

3. Injection

SQL, NoSQL, OS, and LDAP injection remain prevalent.

Example Vulnerability:

// SQL injection via string concatenation
const query = `SELECT * FROM users WHERE name = '${userInput}'`;

Mitigation:

  • Use parameterized queries (prepared statements).
  • Employ an ORM with built-in injection protection.
  • Validate and sanitize all inputs.

Secure Code:

const query = 'SELECT * FROM users WHERE name = ?';
db.query(query, [userInput]);

4. Insecure Design

Flaws in architecture or design pattern, such as missing rate limiting or improper session management.

Example: An e-commerce site allows quantity changes without server-side validation, leading to price manipulation.

Mitigation:

  • Implement a secure design review process.
  • Use threat modeling (e.g., STRIDE) early in the lifecycle.
  • Enforce business logic on the server side.

5. Security Misconfiguration

Default accounts, unpatched systems, verbose error messages, and unsecured cloud storage.

Example:

# File with world-readable permissions
chmod 777 /etc/secrets/keys.json

Mitigation:

Want a personalized diagnostic? Complete our free checklist →

Download checklist
  • Automate configuration management (Ansible, Terraform).
  • Disable directory listing.
  • Remove default accounts and change default credentials.
  • Use .env files or secret management services.

6. Vulnerable and Outdated Components

Using libraries or frameworks with known vulnerabilities.

Example: Using Express.js version 2.x (2015) which has multiple CVEs.

Mitigation:

  • Maintain an inventory of dependencies.
  • Regularly update using tools like npm audit or Dependabot.
  • Subscribe to security advisories for critical packages.

7. Identification and Authentication Failures

Weak passwords, session fixation, and absence of multi-factor authentication (MFA).

Example Vulnerability:

// Session ID set to a predictable user ID
req.session.userId = userId;

Mitigation:

  • Enforce strong password policies.
  • Implement MFA (TOTP, WebAuthn).
  • Use secure, random session identifiers (e.g., crypto.randomUUID()).

8. Software and Data Integrity Failures

Serving malicious JavaScript from compromised CDNs or using unsigned artifacts.

Example: Loading a library from a third-party CDN without Subresource Integrity (SRI).

Mitigation:

  • Use SRI for external scripts and stylesheets.
  • Sign your own artifacts and verify on deployment.
  • Use a software bill of materials (SBOM).

Secure HTML:

<script src="https://cdn.example.com/script.js"
        integrity="sha384-abc123..."
        crossorigin="anonymous"></script>

9. Security Logging and Monitoring Failures

Insufficient logging makes incident detection and response difficult.

Example: Ignoring 5xx errors without logging stack traces or user context.

Mitigation:

  • Log all authentication attempts (success and failure).
  • Centralize logs (ELK stack, Splunk).
  • Alert on anomalies (e.g., burst of 403s).

10. Server-Side Request Forgery (SSRF)

An attacker induces the server to make requests to unintended destinations.

Example Vulnerability:

import requests
url = request.GET.get('url')
response = requests.get(url)  # internal network accessible

Mitigation:

  • Whitelist allowed domains/IPs.
  • Do not expose raw user input to HTTP clients.
  • Use a firewall to restrict outbound traffic.

Secure Code:

allowed_domains = ['api.trusted.com']
parsed = urlparse(url)
if parsed.netloc not in allowed_domains:
    raise ValueError('Forbidden domain')
response = requests.get(url)

Conclusion

The OWASP Top 10 for 2025 reinforces that security is everyone's responsibility. By understanding these risks and applying the mitigations with practical code examples, developers can significantly reduce their attack surface. Remember: security is not a one-time checklist but an ongoing practice integrated into the development lifecycle.

Stay vigilant, stay updated, and always think like an attacker.

References

Ready for the next step? Evaluate your company with our free checklist →

Download checklist

Related posts