OWASP Top 10:2025
Injection

OWASP Top 10:2025 OWASPTOP10-3: A03:2025 Injection Including Cross-Site Scripting

Address OWASP Top 10 A03 Injection per OWASP Top 10:2025. Injection occurs when untrusted data is sent to an interpreter as part of a command or query enabling SQL injection + NoSQL injection + LDAP injection + OS command injection + ORM injection + XML/XPath injection + Server-Side Template Injection (SSTI) + Cross-Site Scripting (XSS) + and other injection variants. Mitigations include (a) validate + sanitise + escape input at trust boundaries + (b) use parameterised queries + prepared statements + ORM safe-query APIs against SQL/NoSQL injection + (c) use context-appropriate output encoding against XSS (HTML + URL + JS + CSS encoding) + (d) implement Content Security Policy + Trusted Types + (e) validate file uploads (type + size + content + scanning) + (f) protect against XXE + deserialisation + template injection via safe parser configuration.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 45 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CWE-20 Improper Input Validation
  • CWE-77 Improper Neutralization of Special Elements used in a Command (Command Injection)
  • CWE-78 Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
  • CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
  • CWE-94 Improper Control of Generation of Code (Code Injection)

IEEE 1686 · 3 controls

  • IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills
  • IEEE1686-Section5.5-5.6-5.7-5.8-Firmware-ConfigSW-TimeSync-DataAtRest IEEE 1686 Section 5.5-5.8 - Firmware Quality + Configuration Software Security + Time Synchronisation + Data Protection at Rest + Patch + Malware + Hardening + Vulnerability
  • IEEE1686-SupplyChain-Documentation-Procurement-ComplianceTable-Physical IEEE 1686 Section 6 IED Security Documentation + Supply Chain + Procurement Specification + Appendix A Compliance Table + Physical and Tamper
  • AQAP2110-1 Quality Management System Aligned to ISO 9001 plus NATO Supplementary Requirements
  • AQAP2110-2 Government Quality Assurance Representative (GQAR) Authority and Access
  • AQAP2110-6 Subcontractor Supply Chain Control plus Counterfeit Material Prevention
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

FedRAMP Rev 5 · 1 control

  • FedRAMP-SupplyChain-SBOM FedRAMP supply chain risk management + SBOM (per EO 14028 + NIST 800-218 SSDF)
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • GAMP5-2nd-Edition-AI-Cloud-Agile-CSA 2nd Edition (2022) - AI/ML, Cloud, Agile, DevOps and Computer Software Assurance (CSA)
  • GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety
  • IATF16949-Clause8-Supplier-QMS-Development-Externally-Provided IATF 16949 Clause 8 Supplier - Control of Externally Provided Processes + Type and Extent + Supplier QMS Development
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain
  • IRM-RiskCategories-Strategic-Financial-Operational-Knowledge-FOIL-External-Internal-DownsideUpside IRM Four Risk Categories - Strategic + Financial + Operational + Knowledge + FOIL Typology + External vs Internal + Downside Threats and Upside Opportunities + Risk Universe
  • A.1 Point-of-Care Testing Additional Requirements

ISO/IEC 27010:2015 · 1 control

  • 27010-15.1 Incident Management

ISO/IEC 27011:2024 · 1 control

  • 27011-5.6 Supplier relationships and telecom supply chain

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • OWASPLLM-4 Supply Chain and Vector/Embedding Weaknesses (LLM03 + LLM08)
  • AODACAN-2 Accessible Procurement of Goods, Services, Facilities
  • 2.7.2 Food Fraud Plan

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 45 it maps to, and the evidence behind each claim, over MCP and REST.