Skip to content
Mermaid templates

OWASP Top 10 (2021)

The current OWASP Top 10 web-application risks as a mindmap with examples.

Template previewMermaid
Rendering…

Make it your own.

mindmap
root((OWASP Top 10 — 2021))
  A01 Broken Access Control
    IDOR
    Missing function-level auth
    Path traversal
  A02 Cryptographic Failures
    Plaintext at rest
    Weak algorithms
    Missing TLS
  A03 Injection
    SQLi
    NoSQLi
    OS command
    LDAP
  A04 Insecure Design
    Missing threat modelling
    Weak rate limits
  A05 Security Misconfiguration
    Default creds
    Verbose errors
    Open S3 buckets
  A06 Vulnerable Components
    Out-of-date libs
    Unpatched CVEs
  A07 Identification & Auth Failures
    Credential stuffing
    Weak session mgmt
  A08 Software / Data Integrity Failures
    Insecure deserialisation
    Tampered CI artifacts
  A09 Security Logging Failures
    No audit logs
    Logs missing critical events
  A10 SSRF
    Cloud metadata IMDS
    Internal scanning