A2:2013-BrokenAuthenticationand SessionManagementA10:2017-InsufficientLogging &MonitoringA9:2017-UsingComponentswith KnownVulnerabilitiesA5:2013-SecurityMisconfigurationA3:2017-SensitiveDataExposureA5:2017-BrokenAccessControlA2:2017-BrokenAuthenticationA1:2013-InjectionC5:2018-ValidateAll InputsC2:2018-LeverageSecurityFrameworksand LibrariesA3:2013-Cross-SiteScripting(XSS)C8:2018-ProtectDataEverywhereA7:2017-Cross-SiteScripting(XSS)C4:2018-Encode andEscape DataC3:2018-SecureDatabaseAccessC10:2018-Handle allErrors andExceptionsC7:2018-EnforceAccessControlsA6:2017-SecurityMisconfigurationA9:2013-UsingComponentswith KnownVulnerabilitiesA10:2013-UnvalidatedRedirectsandForwardsA8:2017-InsecureDeserializationA6:2013-SensitiveDataExposureC6:2018-ImplementDigitalIdentityA4:2013-InsecureDirect ObjectReferencesA1:2017-InjectionC9:2018-ImplementSecurityLogging andMonitoringC1:2018-DefineSecurityRequirementsA7:2013-MissingFunctionLevel AccessControlA8:2013-Cross-SiteRequestForgery(CSRF)A4:2017-XMLExternalEntities(XXE)A2:2013-BrokenAuthenticationand SessionManagementA10:2017-InsufficientLogging &MonitoringA9:2017-UsingComponentswith KnownVulnerabilitiesA5:2013-SecurityMisconfigurationA3:2017-SensitiveDataExposureA5:2017-BrokenAccessControlA2:2017-BrokenAuthenticationA1:2013-InjectionC5:2018-ValidateAll InputsC2:2018-LeverageSecurityFrameworksand LibrariesA3:2013-Cross-SiteScripting(XSS)C8:2018-ProtectDataEverywhereA7:2017-Cross-SiteScripting(XSS)C4:2018-Encode andEscape DataC3:2018-SecureDatabaseAccessC10:2018-Handle allErrors andExceptionsC7:2018-EnforceAccessControlsA6:2017-SecurityMisconfigurationA9:2013-UsingComponentswith KnownVulnerabilitiesA10:2013-UnvalidatedRedirectsandForwardsA8:2017-InsecureDeserializationA6:2013-SensitiveDataExposureC6:2018-ImplementDigitalIdentityA4:2013-InsecureDirect ObjectReferencesA1:2017-InjectionC9:2018-ImplementSecurityLogging andMonitoringC1:2018-DefineSecurityRequirementsA7:2013-MissingFunctionLevel AccessControlA8:2013-Cross-SiteRequestForgery(CSRF)A4:2017-XMLExternalEntities(XXE)

Stash OWASP Bingo - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
  1. A2:2013-Broken Authentication and Session Management
  2. A10:2017-Insufficient Logging & Monitoring
  3. A9:2017-Using Components with Known Vulnerabilities
  4. A5:2013-Security Misconfiguration
  5. A3:2017-Sensitive Data Exposure
  6. A5:2017-Broken Access Control
  7. A2:2017-Broken Authentication
  8. A1:2013-Injection
  9. C5:2018-Validate All Inputs
  10. C2:2018-Leverage Security Frameworks and Libraries
  11. A3:2013-Cross-Site Scripting (XSS)
  12. C8:2018-Protect Data Everywhere
  13. A7:2017-Cross-Site Scripting (XSS)
  14. C4:2018-Encode and Escape Data
  15. C3:2018-Secure Database Access
  16. C10:2018-Handle all Errors and Exceptions
  17. C7:2018-Enforce Access Controls
  18. A6:2017-Security Misconfiguration
  19. A9:2013-Using Components with Known Vulnerabilities
  20. A10:2013-Unvalidated Redirects and Forwards
  21. A8:2017-Insecure Deserialization
  22. A6:2013-Sensitive Data Exposure
  23. C6:2018-Implement Digital Identity
  24. A4:2013-Insecure Direct Object References
  25. A1:2017-Injection
  26. C9:2018-Implement Security Logging and Monitoring
  27. C1:2018-Define Security Requirements
  28. A7:2013-Missing Function Level Access Control
  29. A8:2013-Cross-Site Request Forgery (CSRF)
  30. A4:2017-XML External Entities (XXE)