Free Security Tool

OWASP Risk Calculator

Assess vulnerability risk using the official OWASP Risk Rating Methodology. Calculate likelihood, impact, and overall risk severity. No signup required.

How to use this calculator

  1. Select one option from each factor below, starting with Threat Agent and working down
  2. You don't need to fill every factor: partial results are available as you go
  3. Click Calculate Risk at the bottom to see your overall score
  4. The result combines Likelihood (who + how) with Impact (damage) into a single risk rating

Likelihood Factors

Threat Agent Factors

0/4
Skill Level
How technically skilled is this group of threat agents?
Motive
How motivated is this group of threat agents to find and exploit this vulnerability?
Opportunity
What resources and opportunities are required for this group to exploit this vulnerability?
Size
How large is this group of threat agents?

Vulnerability Factors

0/4
Ease of Discovery
How easy is it for this group to discover this vulnerability?
Ease of Exploit
How easy is it for this group to actually exploit this vulnerability?
Awareness
How well known is this vulnerability to this group of threat agents?
Intrusion Detection
How likely is an exploit to be detected?

Impact Factors

Technical Impact

0/4
Loss of Confidentiality
How much data could be disclosed and how sensitive is it?
Loss of Integrity
How much data could be corrupted and how damaged is it?
Loss of Availability
How much service could be lost and how vital is it?
Loss of Accountability
Are the threat agents' actions traceable to an individual?

Business Impact

0/4
Financial Damage
How much financial damage will result from an exploit?
Reputation Damage
Would an exploit result in reputation damage that would harm the business?
Non-Compliance
How much exposure does non-compliance introduce?
Privacy Violation
How much personally identifiable information could be disclosed?

Want to find real vulnerabilities?

Stop guessing risk scores. Find actual vulnerabilities in your infrastructure. CyberOrbit scans for OWASP Top 10 issues, CVEs, misconfigurations, and 20+ vulnerability classes across a full external pentest.

Request an assessment

The official OWASP Risk Rating Methodology, step by step

This calculator follows the factor model of the official OWASP Risk Rating Methodology, the standard OWASP framework for rating how severe a vulnerability is. It rates risk along two axes: likelihood, which estimates how probable an attack is, and impact, which estimates how damaging it would be. Each axis is built from a set of sub factors you score from 0 to 9, and the tool combines them into an overall risk rating so you can prioritise consistently rather than by gut feel.

How likelihood and impact combine into overall risk

Likelihood factors

  • Threat agent: skill level, motive, opportunity, and group size.
  • Vulnerability: ease of discovery, ease of exploit, awareness, and intrusion detection.

Impact factors

  • Technical: loss of confidentiality, integrity, availability, and accountability.
  • Business: financial damage, reputation damage, non-compliance, and privacy violation.

The tool averages the threat agent and vulnerability factors into a single likelihood score, averages the technical and business factors into a single impact score, then combines the two into an overall risk rating. Scoring both axes is what separates the OWASP method from a purely technical score: a low likelihood, high impact flaw and a high likelihood, low impact flaw can land in very different places.

OWASP risk severity levels

  • Low (0 to 3): acceptable risk. Track it and revisit if the context changes.
  • Medium (3 to 6): address it in the normal course of work.
  • High (6 to 9): address it urgently, ahead of routine work.
  • Critical (9 and above): fix it immediately, it is the top of the queue.

A calculated score tells you how to prioritise, not whether the vulnerability is real. A CyberOrbit assessment finds the actual issues in your environment and rates each one so your risk numbers rest on verified findings.

Frequently asked questions

What is the OWASP Risk Rating Methodology?

It is the official OWASP framework for rating vulnerability severity. It scores likelihood, from threat agent and vulnerability factors, and impact, from technical and business factors, then combines them into an overall risk rating of low, medium, high, or critical.

How does the OWASP risk calculator work?

Select one option for each factor. The calculator averages the likelihood factors and the impact factors, then combines the two into an overall risk score and severity band. You can calculate a partial result at any point and refine it as you add factors.

How is overall risk severity calculated from likelihood and impact?

Likelihood and impact are each scored from 0 to 9 and mapped to low, medium, or high. Combining a higher likelihood with a higher impact produces a higher overall severity, up to critical when both are severe.

How is OWASP risk rating different from CVSS?

CVSS focuses on the technical characteristics of a vulnerability. The OWASP Risk Rating adds business context such as financial damage, reputation, non-compliance, and privacy, which makes it better suited to prioritising work by business risk.

What are the OWASP risk severity levels?

The levels are Low (0 to 3), Medium (3 to 6), High (6 to 9), and Critical (9 and above). Higher bands mean the finding should be fixed sooner.