nerdexam
(ISC)2

CCSP · Question #873

Which of the following is NOT part of the OWASP Top 10 (web application vulnerabilities)?

The correct answer is C. Open Redirect. The classic OWASP Top 10 includes SQLi, XSS, broken access control, etc. Open redirect is a vulnerability but has not been on the most recent OWASP Top 10 lists.

Submitted by eva_at· Apr 18, 2026Cloud Application Security

Question

Which of the following is NOT part of the OWASP Top 10 (web application vulnerabilities)?

Options

  • ASQL Injection
  • BCross-Site Scripting (XSS)
  • COpen Redirect
  • DBroken Access Control

How the community answered

(37 responses)
  • B
    3% (1)
  • C
    95% (35)
  • D
    3% (1)

Explanation

The classic OWASP Top 10 includes SQLi, XSS, broken access control, etc. Open redirect is a vulnerability but has not been on the most recent OWASP Top 10 lists.

Topics

#OWASP Top 10#Web application vulnerabilities#Application security#Cloud security best practices

Community Discussion

No community discussion yet for this question.

Full CCSP Practice