Arsenly
Tools
Free Tools
Pricing
Resources
Sign in Get started
← All tools

PoC / Report Generator

Reference & Reports

Submission-ready bug-bounty & pentest reports - 29 templates, CVSS 3.1 calculator, platform-specific output (HackerOne, Bugcrowd VRT, Intigriti, YesWeHack, Synack, formal pentest), live Markdown preview.

What is PoC / Report Generator?

PoC / Report Generator turns a confirmed bug into a submission-ready report in minutes. Pick a vulnerability template (29 across Injection, Access Control, Authentication, Misconfiguration, Information Disclosure, Business Logic and Cryptography), pick a platform (HackerOne, Bugcrowd, Intigriti, YesWeHack, Synack, Generic Markdown, Formal Pentest) - the tool emits a Markdown report shaped exactly the way that platform’s triage expects.

Every template is pre-populated with CWE / OWASP Top-10 / CVSS 3.1 vector / Bugcrowd VRT plus a curated Description, Steps to Reproduce, Impact, Suggested Fix and References. A built-in CVSS 3.1 base-score calculator (AV / AC / PR / UI / Scope / C / I / A) recomputes the score live and applies it to the severity field with one click.

Output is rendered as live Markdown in the right pane, plus tabs for rendered HTML preview and structured JSON. Copy any format, or download a self-contained .md / styled .html deliverable. Drafts autosave to your browser, so an accidental reload doesn’t lose work. Everything is client-side - nothing about your finding ever leaves your machine.

What it produces

  • 29 vulnerability templates - reflected/stored/DOM XSS, SQLi, NoSQLi, RCE, SSTI, XXE, LFI, IDOR, BAC, CSRF, auth bypass, password-reset poisoning, JWT, OAuth, SSRF, open redirect, CORS, subdomain takeover, security headers, clickjacking, S3 public, info disclosure, exposed .git, rate-limit, race condition, hardcoded secrets - each pre-mapped to CWE / OWASP / CVSS / VRT.
  • Platform-specific layouts - HackerOne (Summary / Steps / Impact), Bugcrowd (VRT-led + Suggested Fix), Intigriti, YesWeHack, Synack (formal classification table), Generic Markdown, Formal Pentest Report (executive summary + business impact + remediation references).
  • CVSS 3.1 calculator - full vector picker with live score & severity, one-click apply to the report.
  • Live Markdown preview - rendered HTML in a side pane as you type.
  • Multi-format export - Markdown, rendered HTML preview, plain text, JSON. Download as .md or styled .html.
  • Draft autosave - localStorage save + restore + auto-recovery on next session. Manual save / restore buttons too.
  • Structured fields - title, severity, CWE, OWASP, VRT, asset URL, reporter, date, description, steps, HTTP request, response, PoC code/HTML, impact, remediation, references.
  • Client-side & private - everything runs in your browser; your findings never touch our servers.

Where it fits in your workflow

  • Submit polished reports to HackerOne / Bugcrowd / Intigriti / YesWeHack / Synack with the correct shape and required metadata pre-filled.
  • Generate the formal pentest finding write-up for a customer-facing deliverable, with the CVSS table and remediation section already structured.
  • Standardise report quality and formatting across a team - pick a template, customise the specifics, ship.
Use PoC / Report Generator

Sign in to access this tool.

Create free account Sign in

At a glance

CategoryReference & Reports
RunsIn your browser
Token cost Free - no tokens
Access Pro
Status● Live

Frequently asked questions

Are reports usable on HackerOne and Bugcrowd?

Yes - the HackerOne output is clean Markdown matching the structure their triage expects (Summary, Steps, Impact). The Bugcrowd output adds the **VRT taxonomy code** in the header, which their triagers explicitly look for. Every template has a sensible default VRT pre-filled.

How accurate is the CVSS calculator?

It implements the CVSS 3.1 specification exactly - ISS, impact, exploitability, scope-changed adjustment and tenths-rounding. Verified against the official FIRST calculator for ~10 reference vectors. Use any vector you like; the score, severity rating and final string are all computed live.

Where do the templates come from?

Curated from OWASP, PortSwigger Web Security Academy, HackerOne / Bugcrowd taxonomies and real bug-bounty report patterns. CWE / CVSS / VRT mappings are the canonical ones each program uses.

Does my report data ever leave my browser?

No. The tool is 100% client-side - no API call, no analytics on report content. Drafts autosave to localStorage on your own machine.

Can I add screenshots / images?

Each platform’s native upload is the right place for screenshots - you submit the Markdown here, then attach images on the platform. For Markdown reports you ship as files, include image links with standard ![alt](url) syntax in any text field.

Explore more tools →