OWASP Top 10 for LLM Applications 2025 report

The OWASP Top 10 for LLM Applications 2025 industry standard compliance report helps you assess your application's security against common vulnerabilities in Large Language Model (LLM) applications.

About the OWASP Top 10 for LLM Applications 2025

The OWASP Top 10 for Large Language Model Applications began in 2023 as a community-driven project to highlight and address security issues specific to AI applications.

As LLM technology continues to spread across industries, the associated risks also evolve. The 2025 list reflects an updated understanding of existing risks and introduces critical updates based on real-world application vulnerabilities.

This report shows how your application complies with the key security controls for developing and operating LLM applications securely.

Covered entities

The OWASP Top 10 for LLM Applications provides guidance and education for organizations that want to adopt LLM applications securely.

OWASP Top 10 for LLM Applications 2025 report vulnerabilities

The following table lists the specific OWASP Top 10 for LLM Applications 2025 vulnerabilities that AppScan Enterprise evaluates. Vulnerabilities found in your application are mapped to these categories.

Table 1. Sections of the regulation
ID Name
LLM01Prompt Injection
LLM02Sensitive Information Disclosure
LLM03Supply Chain
LLM04Data and Model Poisoning
LLM05Improper Output Handling
LLM06Excessive Agency
LLM07System Prompt Leakage
LLM08Vector and Embedding Weaknesses
LLM09Misinformation
LLM10Unbounded Consumption