Frameworks Practical overview of risks OWASP Foundation
OWASP Top 10 for LLM Applications
The OWASP Top 10 describe key security risks in applications built on large language models and outline suitable mitigations.
What this framework governs
The OWASP Foundation is a non-profit dedicated to application security. Its Top 10 lists provide guidance for secure software development and testing.
The list for LLM applications names ten risks, from prompt injection to unbounded consumption, each with typical vulnerabilities, attack scenarios and mitigations.
The list for agentic applications adds the risks of systems that act autonomously, such as agent goal hijacking, tool misuse and the poisoning of memory and context.
Mappings in the threat catalogue
OWASP Top 10 for LLM Applications. Publisher: OWASP Foundation. The Versatile AI Risk Assessment threat catalogue reaches 45 of its 52 threats through this framework, backed by 11 documents at 16 locations. Mappings are documented for 45 of the 52 threats in the catalogue. The overview shows their distribution by topic group.
7 threats without a mapped reference
The catalogue contains no reference from this framework for these threats. This does not establish whether the original document addresses them. See the threat pages for recorded mappings to other frameworks.
- Application Vulnerabilities Application and Integration Security
- Application Denial of Service Attacks on the Running Model and Service
- Profanity Harmful Content
- Harassment Harmful Content
- Unethical Actions Harmful Content
- Social Engineering Malicious Use for Attacks, Fraud and Disinformation
- Fraud Malicious Use for Attacks, Fraud and Disinformation
Analysis: combine several frameworks and see the gaps that remain
Threats referencing this framework (45)
Grouped by topic. Every entry leads to the full threat page.
Agentic and Autonomous AI
5 threatsApplication and Integration Security
6 threatsAttacks on the Running Model and Service
6 threatsHarmful Content
6 threatsMalicious Use for Attacks, Fraud and Disinformation
2 threatsModel and Training Data Manipulation
4 threatsPrivacy and Data Leakage
4 threatsPrompt Attacks and Guardrail Evasion
5 threatsReliability and Responsible Use
4 threatsSupply Chain and Provenance
3 threatsNo threat matches this input. Reset the filters to see all of them again.
Sources used (11)
These exact versions are pinned in the catalogue. Every page states the publisher, the version used, the locations and the referencing threats.
This page does not reproduce the text of the standards. It states the identifier, title and location; the wording itself is in the original document. The mappings are taxonomic and not evidence of compliance.
The Top 10 help teams prioritise development work and security testing. They do not amount to a comprehensive security assessment or certification.
Further frameworks
The frameworks address different aspects: legal requirements, organisational risk management and technical security. Explore the further perspectives included in the catalogue.
From the framework to the assessment
The full catalogue states the mitigations, the possible impact and every verified location for each threat. The live demo runs locally in your browser, with no sign-up.
Cite this page
For reports, policies or internal documents; the link leads directly to this framework page.
“OWASP Top 10 for LLM Applications” (OWASP Foundation). Mappings in the AI threat catalogue, Versatile AI Risk Assessment, as of July 2026. https://www.versatile-ai-risk-assessment.com/en/wissensbasis/frameworks/owasp-top-10-llm-applications/