TL;DR: This year, OWASP did something it’s never done before.
It checked.
If you rank these risks using only public incident data, prompt injection fell out of the top ten list entirely. It wasn’t first, it wasn’t fifth, it was gone. Expert opinion is still opinion.
So what the hell happened?