OWASP Top 10 for Business Applications
What these risks actually look like inside point-of-sale systems, APIs and payment integrations — and the first check to run on each one.
Read the articleThe ten risk categories
- A01
- A02
- A03
- A04
- A05
- A06
- A07
- A08
- A09
- A10
The ten risk categories, in the order OWASP lists them. Each is assessed against the request path below.
Request path we assess
- Untrusted input
- Server-side validation
- Authorised business logic
- Audited data store