The document provides information about changes made to the OWASP Top 10 document between 2010 and 2013. It notes that Broken Authentication and Session Management moved up in prevalence based on data, while Cross-Site Request Forgery moved down. It broadened the Failure to Restrict URL Access category to be more inclusive of function-level access control issues. A new category of Sensitive Data Exposure was created by merging and broadening previous categories related to insecure storage and transport of sensitive data. A new category of Using Known Vulnerable Components was also added to call attention to this growing risk area.