What is OWASP Top 10?

The OWASP Top 10 is a regularly updated list of the ten most critical web application security risks, published by the Open Worldwide Application Security Project. It serves as a widely accepted baseline for web application security testing and is referenced by compliance frameworks including PCI DSS. Penetration testers commonly use the OWASP Top 10 as a minimum checklist when assessing web applications.