OWASP Risk Calculator
Assess vulnerability risk using the official OWASP Risk Rating Methodology. Calculate likelihood, impact, and overall risk severity. No signup required.
How to use this calculator
- Select one option from each factor below, starting with Threat Agent and working down
- You don't need to fill every factor: partial results are available as you go
- Click Calculate Risk at the bottom to see your overall score
- The result combines Likelihood (who + how) with Impact (damage) into a single risk rating
Likelihood Factors
Threat Agent Factors
0/4Vulnerability Factors
0/4Impact Factors
Technical Impact
0/4Business Impact
0/4Want to find real vulnerabilities?
Stop guessing risk scores. Find actual vulnerabilities in your infrastructure. CyberOrbit scans for OWASP Top 10 issues, CVEs, misconfigurations, and 20+ vulnerability classes across a full external pentest.
What is the OWASP Risk Rating Methodology?
The OWASP Risk Rating Methodology is a standardized framework for assessing the severity of security vulnerabilities. It evaluates risk based on two dimensions: Likelihood (how probable is an attack?) and Impact (how bad would it be?). Each dimension uses multiple sub-factors scored from 0-9 to produce an overall risk rating of LOW, MEDIUM, HIGH, or CRITICAL.
How Is Risk Calculated?
Likelihood Factors
- Threat Agent: Skill, motive, opportunity, size
- Vulnerability: Ease of discovery, ease of exploit, awareness, detection
Impact Factors
- Technical: Confidentiality, integrity, availability, accountability
- Business: Financial, reputation, compliance, privacy
Frequently Asked Questions
What is the OWASP Risk Rating Methodology?
It's a standardized framework from OWASP for assessing vulnerability severity. It combines likelihood factors (threat agent capability, vulnerability ease of exploit) with impact factors (technical and business damage) to produce a risk score from 0-9.
How is this different from CVSS?
CVSS focuses on technical characteristics of a vulnerability. OWASP Risk Rating adds business context: financial damage, reputation impact, compliance risk, and privacy implications. This makes it better suited for prioritizing remediation based on business risk.
Do I need to fill in every factor?
No, you can get a partial risk calculation with any subset of factors. However, filling in all 16 factors gives the most accurate result. At minimum, select at least one factor from each of the four groups.
Is this tool free?
Yes, completely free with no signup required. For automated vulnerability discovery and risk assessment across your infrastructure, try a free CyberOrbit assessment.