Submission-ready bug-bounty & pentest reports - 29 templates, CVSS 3.1 calculator, platform-specific output (HackerOne, Bugcrowd VRT, Intigriti, YesWeHack, Synack, formal pentest), live Markdown preview.
PoC / Report Generator turns a confirmed bug into a submission-ready report in minutes. Pick a vulnerability template (29 across Injection, Access Control, Authentication, Misconfiguration, Information Disclosure, Business Logic and Cryptography), pick a platform (HackerOne, Bugcrowd, Intigriti, YesWeHack, Synack, Generic Markdown, Formal Pentest) - the tool emits a Markdown report shaped exactly the way that platform’s triage expects.
Every template is pre-populated with CWE / OWASP Top-10 / CVSS 3.1 vector / Bugcrowd VRT plus a curated Description, Steps to Reproduce, Impact, Suggested Fix and References. A built-in CVSS 3.1 base-score calculator (AV / AC / PR / UI / Scope / C / I / A) recomputes the score live and applies it to the severity field with one click.
Output is rendered as live Markdown in the right pane, plus tabs for rendered HTML preview and structured JSON. Copy any format, or download a self-contained .md / styled .html deliverable. Drafts autosave to your browser, so an accidental reload doesn’t lose work. Everything is client-side - nothing about your finding ever leaves your machine.
.md or styled .html.Yes - the HackerOne output is clean Markdown matching the structure their triage expects (Summary, Steps, Impact). The Bugcrowd output adds the **VRT taxonomy code** in the header, which their triagers explicitly look for. Every template has a sensible default VRT pre-filled.
It implements the CVSS 3.1 specification exactly - ISS, impact, exploitability, scope-changed adjustment and tenths-rounding. Verified against the official FIRST calculator for ~10 reference vectors. Use any vector you like; the score, severity rating and final string are all computed live.
Curated from OWASP, PortSwigger Web Security Academy, HackerOne / Bugcrowd taxonomies and real bug-bounty report patterns. CWE / CVSS / VRT mappings are the canonical ones each program uses.
No. The tool is 100% client-side - no API call, no analytics on report content. Drafts autosave to localStorage on your own machine.
Each platform’s native upload is the right place for screenshots - you submit the Markdown here, then attach images on the platform. For Markdown reports you ship as files, include image links with standard  syntax in any text field.