OWASP Top Ten Data Collection is Open
Data Collection: Now - December 2024

It's time to get machinery running again and figure out what the next OWASP Top Ten is going to look like for 2024. The last two cycles have worked out well for us, so we are going to continue to use the same process for data collection and the same templates as the 2021 collection process. You can find more details in Github or in the README folder behind the bit.ly link which points to a SharePoint folder that will automatically move submissions to Azure blob storage for processing.
Templates: https://github.com/OWASP/Top10/tree/master/2024/Data
Contribution Process
There are a few ways that data can be contributed:
- Email a CSV/Excel/JSON file with the dataset(s) to brian.glas@owasp.org
- Upload a CSV/Excel/JSON file to https://bit.ly/OWASPTop10Data
We plan to accept contributions to the Top 10 2024 during Jun-Dec of 2024 for data dating from 2021 to current.
We have both CSV and JSON templates to aid in normalizing contributions: https://github.com/OWASP/Top10/tree/master/2024/Data
The following data elements are *required or optional:
Per DataSet:
- Contributor Name (org or anon)
- Contributor Contact Email
- Time period (2023, 2022, 2021)
- *Number of applications tested
- *CWEs w/ number of applications found in
- Type of testing (TaH, HaT, Tools)
- Primary Language (code)
- Geographic Region (Global, North America, EU, Asia, other)
- Primary Industry (Multiple, Financial, Industrial, Software, ??)
- Whether or not data contains retests or the same applications multiple times (T/F)
If a contributor has two types of datasets, one from HaT and one from TaH sources, then it is recommended to submit them as two separate datasets.
AnalysisWe will conduct analysis of the data, in a similar manner as the 2021 and hope to also include some trending data over both the 2021 and 2024 collection time periods.
Timeline
Data Collection: Jun - Dec
Analysis: Early 2025
Draft: Early 2025
Release: First half of 2025

