The OWASP Top 10 for LLM Applications
The community-standard risk list for LLM applications, walked entry by entry and mapped onto this site — plus how to actually use it.
Content last verified 2026-09.
Lessons
Sources
- OWASP GenAI Security Project — Top 10 for LLM Applications (2025)
- Greshake et al. (2023) — Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection
- Carlini et al. (2020) — Extracting Training Data from Large Language Models
- Ganguli et al. (2022) — Red Teaming Language Models to Reduce Harms