A5:2017-BrokenAccessControlA5:2013-SecurityMisconfigurationA1:2013-InjectionA3:2013-Cross-SiteScripting(XSS)C2:2018-LeverageSecurityFrameworksand LibrariesA3:2017-SensitiveDataExposureC5:2018-ValidateAll InputsA4:2017-XMLExternalEntities(XXE)C6:2018-ImplementDigitalIdentityA6:2013-SensitiveDataExposureA10:2013-UnvalidatedRedirectsandForwardsA1:2017-InjectionA4:2013-InsecureDirect ObjectReferencesA7:2013-MissingFunctionLevel AccessControlA10:2017-InsufficientLogging &MonitoringC1:2018-DefineSecurityRequirementsA8:2017-InsecureDeserializationA8:2013-Cross-SiteRequestForgery(CSRF)C10:2018-Handle allErrors andExceptionsA9:2013-UsingComponentswith KnownVulnerabilitiesA7:2017-Cross-SiteScripting(XSS)C7:2018-EnforceAccessControlsC4:2018-Encode andEscape DataC8:2018-ProtectDataEverywhereC3:2018-SecureDatabaseAccessC9:2018-ImplementSecurityLogging andMonitoringA9:2017-UsingComponentswith KnownVulnerabilitiesA2:2017-BrokenAuthenticationA6:2017-SecurityMisconfigurationA2:2013-BrokenAuthenticationand SessionManagementA5:2017-BrokenAccessControlA5:2013-SecurityMisconfigurationA1:2013-InjectionA3:2013-Cross-SiteScripting(XSS)C2:2018-LeverageSecurityFrameworksand LibrariesA3:2017-SensitiveDataExposureC5:2018-ValidateAll InputsA4:2017-XMLExternalEntities(XXE)C6:2018-ImplementDigitalIdentityA6:2013-SensitiveDataExposureA10:2013-UnvalidatedRedirectsandForwardsA1:2017-InjectionA4:2013-InsecureDirect ObjectReferencesA7:2013-MissingFunctionLevel AccessControlA10:2017-InsufficientLogging &MonitoringC1:2018-DefineSecurityRequirementsA8:2017-InsecureDeserializationA8:2013-Cross-SiteRequestForgery(CSRF)C10:2018-Handle allErrors andExceptionsA9:2013-UsingComponentswith KnownVulnerabilitiesA7:2017-Cross-SiteScripting(XSS)C7:2018-EnforceAccessControlsC4:2018-Encode andEscape DataC8:2018-ProtectDataEverywhereC3:2018-SecureDatabaseAccessC9:2018-ImplementSecurityLogging andMonitoringA9:2017-UsingComponentswith KnownVulnerabilitiesA2:2017-BrokenAuthenticationA6:2017-SecurityMisconfigurationA2:2013-BrokenAuthenticationand SessionManagement

Stash OWASP Bingo - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
  1. A5:2017-Broken Access Control
  2. A5:2013-Security Misconfiguration
  3. A1:2013-Injection
  4. A3:2013-Cross-Site Scripting (XSS)
  5. C2:2018-Leverage Security Frameworks and Libraries
  6. A3:2017-Sensitive Data Exposure
  7. C5:2018-Validate All Inputs
  8. A4:2017-XML External Entities (XXE)
  9. C6:2018-Implement Digital Identity
  10. A6:2013-Sensitive Data Exposure
  11. A10:2013-Unvalidated Redirects and Forwards
  12. A1:2017-Injection
  13. A4:2013-Insecure Direct Object References
  14. A7:2013-Missing Function Level Access Control
  15. A10:2017-Insufficient Logging & Monitoring
  16. C1:2018-Define Security Requirements
  17. A8:2017-Insecure Deserialization
  18. A8:2013-Cross-Site Request Forgery (CSRF)
  19. C10:2018-Handle all Errors and Exceptions
  20. A9:2013-Using Components with Known Vulnerabilities
  21. A7:2017-Cross-Site Scripting (XSS)
  22. C7:2018-Enforce Access Controls
  23. C4:2018-Encode and Escape Data
  24. C8:2018-Protect Data Everywhere
  25. C3:2018-Secure Database Access
  26. C9:2018-Implement Security Logging and Monitoring
  27. A9:2017-Using Components with Known Vulnerabilities
  28. A2:2017-Broken Authentication
  29. A6:2017-Security Misconfiguration
  30. A2:2013-Broken Authentication and Session Management