Learn the OWASP Top 10
Clear, practical lessons on the most critical security risks — across Web, API, Mobile, and LLM applications. Every edition, focused on the latest, easy to navigate.
Choose a category
Pick an area, then an edition — the most recent is selected by default.Web Application Top 10
The original OWASP Top 10 — the most critical security risks to web applications.
API Security Top 10
Risks specific to APIs — object/function authorization, resource consumption, and more.
Mobile Top 10
The OWASP Mobile Top 10 (2024) — the top risks for mobile applications.
LLM & GenAI Top 10
The OWASP Top 10 for Large Language Model applications — prompt injection, agents, RAG, and more.
▪ Cheat sheets
Quick, one-page references for every vulnerability — what it is, how it’s attacked, and how to prevent it.
▪ Practice locally
Hands-on vulnerable labs you run on your own machine with Docker or a Codespace — never exposed online.
▪ Official OWASP ↗
The canonical OWASP Top 10 projects and documentation on owasp.org.