# Vulnerability Report Template

## Ethical Use Notice
This report is for an authorized security assessment. Do not test, exploit, or
access systems outside the written scope and rules of engagement.

## Finding Summary
- Title:
- Severity: Critical / High / Medium / Low / Informational
- CVSS vector and score:
- Affected asset(s):
- Discovery date:
- Reporter:
- Status: Open / Accepted Risk / Fixed / Retest Passed

## Executive Summary
Describe the business risk in plain language and identify who can act on it.

## Technical Details
- Endpoint / host / component:
- Preconditions:
- Root cause:
- Security control gap:

## Evidence
Include minimal screenshots, logs, request/response excerpts, or hashes needed to
support the finding. Redact secrets and personal data.

## Impact
Explain realistic impact within the authorized environment. Avoid overstating
impact that was not demonstrated or supported by evidence.

## Reproduction Steps
Document safe, non-destructive validation steps that the asset owner can repeat.

## Remediation
- Immediate containment:
- Long-term fix:
- Verification method:

## References
- CWE:
- OWASP category:
- Vendor advisory:
