On April 19th, OWASP released the final version of the Top 10 for 2010. The OWASP Top Ten provides a powerful awareness document for web application security. This version was updated based on comments received during the comment period after the release candidate was released in Nov. 2009. Click this link to download the OWASP Top 10 Web Application Security Vulnerabilities for 2010 (PDF 2.16MB) The OWASP Top 10 Web Application Security Risks for 2010 are: A1: Injection A2: Cross-Site Scripting (XSS) A3: Broken Authentication and Session Management A4: Insecure Direct Object References A5: Cross-Site Request Forgery (CSRF) A6: Security Misconfiguration A7: Insecure Cryptographic Storage A8: Failure to Restrict URL Access A9: Insufficient Transport Layer Protection A10: Unvalidated Redirects and Forwards OWASP is reaching out to developers, not just the application security community. The Top 10 is about managing risk, not just avoiding vulnerabilities. To manage these risks, organizations need an application risk management program, not just awareness training, app testing, and remediation.