Cyber Resilience

A05:2025 Injection

OWASP Top 10:2025 · Back to the list

Untrusted input crosses an interpreter boundary without proper neutralization. SQL, OS command, LDAP, XSS, template injection.

Related on the LLM side: OWASP Top 10 for LLMs LLM01:2025.

Member CWEs (37)

Mapped NIST 800-53 r5 controls (1)

Our two-way, human-QA’d reading of how this category and each NIST 800-53 control relate. No external body publishes an OWASP→800-53 mapping, so these are our assessment.

Direction: other covers this; this covers other (F/M/P = full / mostly / partial).

Tagged CVEs (showing 50 most recent of 95,935)

Data: OWASP Top 10:2025 (CC BY-SA 4.0) · CWE memberships from cwe-api.mitre.org (meta-category CWE-1440).