---
title: "22 Years of OWASP Top 10: Webinar with Dave Wichers"
description: Only three of the original 2003 OWASP Top 10 risks are unchanged. Dave Wichers, co-founder, on what 22 years of the list actually tells us.
image: https://www.appsecai.io/hubfs/Blog%20Posts/Updated%20image.png
---

<https://www.appsecai.io/blog/22-years-of-owasp-top-10#body>

[![Logo. Blue. Horizontal](https://www.appsecai.io/hubfs/Logo.%20Blue.%20Horizontal.svg "Logo. Blue. Horizontal")](https://www.appsecai.io)

- Open submenu for Products 
  
    - [Expert Fix Automation](https://www.appsecai.io/expert-fix-automation)
    - [Expert Triage Automation](https://www.appsecai.io/expert-triage-automation-eta)
- Open submenu for By Role 
  
    - [Application Security Teams](https://www.appsecai.io/application-security-teams)
    - [Product Security](https://www.appsecai.io/product-security)
    - [CISOs](https://www.appsecai.io/application-security-for-cisos)
    - [Vulnerability Management](https://www.appsecai.io/vulnerability-management)
    - [Engineering Leaders](https://www.appsecai.io/engineering-security-automation)
- Open submenu for Resources 
  
    - [Blog](https://www.appsecai.io/blog)
    - [Case Studies](https://www.appsecai.io/case-studies)
    - [AppSec - Complete Guide in AI Era](https://www.appsecai.io/application_security_complete_guide)
    - [Videos & Podcasts](https://www.appsecai.io/videos-podcasts)
    - [Return on Investment Calculator](https://www.appsecai.io/roi)
    - [Performance Metrics](https://www.appsecai.io/performance-metrics)
    - [AI Security Book](https://www.appsecai.io/the-ai-security-advantage-by-bruce-fram)
    - [Partners](https://www.appsecai.io/partners)
- [Pricing](https://www.appsecai.io/pricing)
- [About](https://www.appsecai.io/about)
  
   Show submenu for About 
  
    - [Leadership Team](https://www.appsecai.io/about#leadership)

- Open submenu for Products 
  
    - [Expert Fix Automation](https://www.appsecai.io/expert-fix-automation)
    - [Expert Triage Automation](https://www.appsecai.io/expert-triage-automation-eta)
- Open submenu for By Role 
  
    - [Application Security Teams](https://www.appsecai.io/application-security-teams)
    - [Product Security](https://www.appsecai.io/product-security)
    - [CISOs](https://www.appsecai.io/application-security-for-cisos)
    - [Vulnerability Management](https://www.appsecai.io/vulnerability-management)
    - [Engineering Leaders](https://www.appsecai.io/engineering-security-automation)
- Open submenu for Resources 
  
    - [Blog](https://www.appsecai.io/blog)
    - [Case Studies](https://www.appsecai.io/case-studies)
    - [AppSec - Complete Guide in AI Era](https://www.appsecai.io/application_security_complete_guide)
    - [Videos & Podcasts](https://www.appsecai.io/videos-podcasts)
    - [Return on Investment Calculator](https://www.appsecai.io/roi)
    - [Performance Metrics](https://www.appsecai.io/performance-metrics)
    - [AI Security Book](https://www.appsecai.io/the-ai-security-advantage-by-bruce-fram)
    - [Partners](https://www.appsecai.io/partners)
- [Pricing](https://www.appsecai.io/pricing)
- [About](https://www.appsecai.io/about)
  
   Show submenu for About 
  
    - [Leadership Team](https://www.appsecai.io/about#leadership)

- [Demo Video](https://www.appsecai.io/demo)
- [Schedule Demo](https://calendly.com/brucefram/30min)

- [Demo Video](https://www.appsecai.io/demo)
- [Schedule Demo](https://calendly.com/brucefram/30min)

![22 Years of OWASP Top 10: Webinar with Co-Founder Dave Wichers](https://www.appsecai.io/hubfs/Blog%20Posts/Updated%20image.png)

# *[Analysis](https://www.appsecai.io/blog/tag/analysis)* 22 Years of OWASP Top 10: Webinar with Co-Founder Dave Wichers

Only three of the original 2003 OWASP Top 10 risks are unchanged. Dave Wichers, co-founder, on what 22 years of the list actually tells us.

## *Share*

- [mailto:?&subject=22%20Years%20of%20OWASP%20Top%2010:%20Webinar%20with%20Co-Founder%20Dave%20Wichers&body=22%20Years%20of%20OWASP%20Top%2010:%20Webinar%20with%20Co-Founder%20Dave%20Wichers%0A(https%3A%2F%2Fwww.appsecai.io%2Fblog%2F22-years-of-owasp-top-10)](mailto:?&subject=22%20Years%20of%20OWASP%20Top%2010:%20Webinar%20with%20Co-Founder%20Dave%20Wichers&body=22%20Years%20of%20OWASP%20Top%2010:%20Webinar%20with%20Co-Founder%20Dave%20Wichers%0A(https%3A%2F%2Fwww.appsecai.io%2Fblog%2F22-years-of-owasp-top-10))
- <https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.appsecai.io%2Fblog%2F22-years-of-owasp-top-10&title=22%20Years%20of%20OWASP%20Top%2010:%20Webinar%20with%20Co-Founder%20Dave%20Wichers&summary=&source=>
- <https://twitter.com/intent/tweet?text=22+Years+of+OWASP+Top+10%3A+Webinar+with+Co-Founder+Dave+Wichers&url=(https%3A%2F%2Fwww.appsecai.io%2Fblog%2F22-years-of-owasp-top-10)>
- <https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.appsecai.io%2Fblog%2F22-years-of-owasp-top-10>

Here's a question that might surprise you: After 22 years of OWASP Top 10 guidance, how many of the original 2003 vulnerabilities remain fundamentally unchanged?

The answer is three. Just three out of ten.

Buffer overflows? Gone. Application denial of service? Obsolete. But broken access control, injection flaws, and security misconfigurations? Still dominating breach reports in 2025, with broken access control claiming the #1 spot.

This evolution tells a story about what actually works in application security, and what doesn't.

 

 

## Why This Conversation Matters

On December 4th, we're hosting a discussion with someone uniquely positioned to decode these patterns: [Dave Wichers](https://www.linkedin.com/in/wichers/), co-founder of the OWASP Top 10 project and its leader for 15 years. Dave also created the OWASP Benchmark Project and recently collaborated with AppSecAI on our [Python Benchmark contribution](https://www.appsecai.io/blog/we-just-gave-python-security-testing-a-much-needed-upgrade-and-its-free) to the community.

This isn't a vendor pitch or product demo. Dave will share his perspective on the data, methodology, and trends he's observed across two decades of vulnerability analysis.

We'll explore what the persistence of certain risk categories reveals about the fundamental challenges in application security.

## **What You'll Learn**

The Historical Context: From "Unvalidated Input" in 2003 to "Supply-Chain Failures" in 2025, we'll trace how expanding trust boundaries reshaped our security priorities. The evolution from defensive coding to defensive systems design reflects the growing sophistication and increasing complexity of our industry.

The Data Behind the Changes: Why did some vulnerabilities disappear while others persist? The patterns reveal important insights about what security interventions actually work at scale versus what remains stubbornly resistant to traditional approaches.

The Economics Reality: Our CEO [Bruce Fram,](https://www.linkedin.com/in/bruce-fram/) will discuss how automated remediation aligns with the realities the Top 10 reveals, particularly as vulnerability backlogs continue growing faster than teams can triage them. When SQL injection fixes still consume weeks of developer time in 2025, something needs to change.

Looking Forward: The Top 10 represents testing capabilities from recent years, but understanding these historical patterns helps security teams anticipate where testing needs to evolve and where traditional manual approaches create impossible economics.

## **Perfect Timing for 2026 Planning**

As security leaders finalize 2026 budgets and strategies, this historical perspective provides valuable context for investment decisions. Which approaches have proven their worth over decades? Where are the persistent gaps that new technologies might finally address?

Dave's insights will help you as AI and automation reshape what's possible in application security.

## **Join the Conversation**

Date: December 4, 2025  
Time: 12:00 PM Eastern  
Duration: 30 minutes + Q&A  
Format: Live discussion with Q&A  
Cost: Free

[Register Here for Free Access](https://bit.ly/47ROJLn)

We'll record the session, but the live Q&A is where the real insights emerge. Bring your questions about OWASP methodology, historical trends, or how current data might inform future security strategies.

This conversation builds on our commitment to community contribution over competition. Just as our Python Benchmark work with Dave advances the entire field, this discussion aims to benefit all application security practitioners... regardless of their current tool choices.

Sometimes the best way to plan for the future is understanding what we've learned from the past. Join us on December 4th for that conversation!

---

*About the Speakers: Dave Wichers co-founded the OWASP Top 10 project in 2003 and led it for 15 years. Bruce Fram is CEO of AppSecAI, focused on results-based application security automation.*

Want to learn more? Check out our book, [The AI Security Advantage](https://www.appsecai.io/blog/the-math-finally-adds-up-the-ai-security-advantage-is-here), available now! 

## **You May Also Like**

#### [![Introducing OWASP OASIS, a New Initiative to Fight Back Against AI and Human Exploits of Open Source Software Vulnerabilities](https://www.appsecai.io/hubfs/Web%20Site/owasp-oasis-community-validated.webp) *Aug 26, 2026, 5:00:00 AM | News* Introducing OWASP OASIS, a New Initiative to Fight Back Against AI and Human Exploits of Open Source Software Vulnerabilities](https://www.appsecai.io/blog/introducing-owasp-oasis)

#### [![What 22 Years of OWASP Top 10 Really Tells Us About AppSec](https://www.appsecai.io/hubfs/Blog%20Posts/Screenshot%202025-12-04%20123837.webp) *Dec 10, 2025, 10:30:00 AM | Analysis* What 22 Years of OWASP Top 10 Really Tells Us About AppSec](https://www.appsecai.io/blog/what-22-years-of-owasp-top-10-really-tells-us-about-appsec)

#### [![Dear CISOs: The Economics of Cybersecurity Just Changed Forever](https://www.appsecai.io/hubfs/Blog%20Posts/Blog%20image%20styles%20(Twitter%20Post)%20(13).webp) *Dec 31, 2025, 10:30:00 AM | Remediation $* Dear CISOs: The Economics of Cybersecurity Just Changed Forever](https://www.appsecai.io/blog/dear-cisos-the-economics-of-cybersecurity-just-changed-forever)

[See All Posts](https://www.appsecai.io/blog)

[![Logo. White. Horizontal](https://www.appsecai.io/hubfs/Logo.%20White.%20Horizontal.svg "Logo. White. Horizontal")](https://www.appsecai.io/)

**Automation for   
Application Security Teams**

<https://www.linkedin.com/company/appsecai-inc/> <https://www.youtube.com/@AppSecAI>

- Products 
    - [Expert Fix Automation (EFA)](https://www.appsecai.io/expert-fix-automation)
    - [Expert Triage Automation (ETA)](https://www.appsecai.io/expert-triage-automation-eta)
    - [Try Now!](https://www.appsecai.io/try-now)

- By Role 
    - [Application Security Teams](https://www.appsecai.io/application-security-teams)
    - [Product Security](https://www.appsecai.io/product-security)
    - [Vulnerability Management](https://www.appsecai.io/vulnerability-management)
    - [CISOs](https://www.appsecai.io/application-security-for-cisos)
    - [Engineering Leaders](https://www.appsecai.io/engineering-security-automation)

- Resources 
    - [Blog](https://www.appsecai.io/blog)
    - [Case Studies](https://www.appsecai.io/case-studies)
    - [Videos & Podcasts](https://www.appsecai.io/videos-podcasts)
    - [AI Security Book](https://www.appsecai.io/the-ai-security-advantage-by-bruce-fram)
    - [Metrics](https://www.appsecai.io/performance-metrics)
    - [ROI Calculator](https://www.appsecai.io/roi)
    - [Pricing](https://www.appsecai.io/pricing)

- Company 
    - [About](https://www.appsecai.io/about)
    - [Partners](https://www.appsecai.io/partners)
    - [Careers](https://www.appsecai.io/careers)
    - [Contact Us](https://www.appsecai.io/contact)
    - [Privacy Policy](https://www.appsecai.io/privacy-policy)
    - [Terms of Service](https://www.appsecai.io/terms-of-service)
    - [Cookie Policy](https://www.appsecai.io/cookie-policy)

---

© 2026 AppSecAI, Inc. All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.appsecai.io/#org",
  "@type" : "Organization",
  "contactPoint" : [ {
    "@type" : "ContactPoint",
    "availableLanguage" : [ "en" ],
    "contactType" : "sales",
    "email" : "automation@appsecai.io"
  }, {
    "@type" : "ContactPoint",
    "availableLanguage" : [ "en" ],
    "contactType" : "security",
    "email" : "security@appsecai.io"
  }, {
    "@type" : "ContactPoint",
    "availableLanguage" : [ "en" ],
    "contactType" : "privacy",
    "email" : "privacy@appsecai.io"
  } ],
  "logo" : {
    "@type" : "ImageObject",
    "height" : 112,
    "url" : "https://43994771.fs1.hubspotusercontent-na2.net/hubfs/43994771/Logos/Logo.%20Blue.%20Stacked-1.png",
    "width" : 112
  },
  "name" : "AppSecAI, Inc.",
  "sameAs" : [ "https://www.linkedin.com/company/appsecai-inc/", "https://www.youtube.com/@AppSecAI" ],
  "url" : "https://www.appsecai.io/"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.appsecai.io/#website",
  "@type" : "WebSite",
  "inLanguage" : "en-US",
  "name" : "AppSecAI",
  "publisher" : {
    "@id" : "https://www.appsecai.io/#org"
  },
  "url" : "https://www.appsecai.io/"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.appsecai.io/blog/22-years-of-owasp-top-10/#post",
  "@type" : "BlogPosting",
  "articleSection" : "Industry Insights",
  "author" : {
    "@type" : "Person",
    "name" : "Bruce Fram"
  },
  "dateModified" : "2025-11-20T20:00:00Z",
  "datePublished" : "2025-11-20T20:00:00Z",
  "description" : "Join us on December 4, 2025 | 12:00 PM ET Free Registration, Bring your questions!",
  "headline" : "22 Years of OWASP Top 10: Webinar with Co-Founder Dave Wichers",
  "image" : {
    "@type" : "ImageObject",
    "height" : 900,
    "url" : "https://43994771.fs1.hubspotusercontent-na2.net/hubfs/43994771/Blog%20Posts/OWASP%202025%20Top%2010%20%20(1).webp",
    "width" : 1600
  },
  "inLanguage" : "en-US",
  "keywords" : "OWASP Top 10, Dave Wichers, application security webinar, AppSec evolution, vulnerability management, security automation",
  "mainEntityOfPage" : {
    "@id" : "https://www.appsecai.io/blog/22-years-of-owasp-top-10/#webpage",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@id" : "https://www.appsecai.io/#org"
  },
  "url" : "https://www.appsecai.io/blog/22-years-of-owasp-top-10",
  "wordCount" : 580
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.appsecai.io/blog/author/bruce-fram#author",
  "@type" : "Person",
  "email" : "bruce@appsecai.io",
  "name" : "Bruce Fram",
  "sameAs" : [ "https://www.linkedin.com/in/bruce-fram/", "http://www.appsecai.io" ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.appsecai.io/blog/22-years-of-owasp-top-10#blogposting",
  "@type" : "BlogPosting",
  "author" : {
    "@id" : "https://www.appsecai.io/blog/author/bruce-fram#author"
  },
  "commentCount" : 0,
  "dateModified" : "2024-10-01T12:0000+0000",
  "datePublished" : "2025-11-20T20:0000+0000",
  "headline" : "22 Years of OWASP Top 10: Webinar with Co-Founder Dave Wichers",
  "image" : "https://www.appsecai.io/blog/22-years-of-owasp-top-10",
  "inLanguage" : "en",
  "keywords" : [ "Analysis" ],
  "mainEntityOfPage" : "https://www.appsecai.io/blog/22-years-of-owasp-top-10",
  "name" : "22 Years of OWASP Top 10: Webinar with Co-Founder Dave Wichers",
  "publisher" : {
    "@id" : "https://www.yourdomain.com#organization"
  },
  "url" : "https://www.appsecai.io/blog/22-years-of-owasp-top-10",
  "wordCount" : 583
}
```