A real sample penetration test report
This is exactly what a customer's security team or your auditor receives - a redacted TurboPentest report with CVSS-scored findings, proof-of-concept, and remediation. See it before you buy.
Penetration Test Report
ginandjuice.shop · 2026-03-29
Executive Summary
An automated black-box pentest identified 18 findings across all severity levels. The most severe include a complete admin panel access-control bypass (CVSS 10.0), plaintext credential disclosure, SQL injection, and blind XXE injection - each with proof-of-concept and remediation steps.
4
Critical
7
High
4
Medium
2
Low
1
Info
Admin Panel Access Control Bypass via X-Original-URL Header
Includes reproduction steps, proof-of-exploit, and remediation.
What's in the report
- ✓Executive summary written for non-technical stakeholders
- ✓Findings ranked by severity, each with a CVSS score
- ✓OWASP Top 10 mapping for every finding
- ✓Proof-of-concept and steps to reproduce
- ✓Remediation guidance your developers can act on
- ✓Attack surface map (endpoints, ports, technologies, auth)
- ✓STRIDE threat model for manual follow-up
- ✓Signed third-party attestation letter for auditors and customers
Pentest report FAQ
What does a penetration test report include?
A good pentest report includes an executive summary, findings ordered by severity with CVSS scores and OWASP mapping, proof-of-concept and steps to reproduce each issue, remediation guidance, an attack surface map, a threat model, and a signed attestation letter you can share with auditors and customers. The TurboPentest sample above shows exactly that format.
Can I use this as a pentest report template?
Yes - the sample shows the structure a professional penetration test report follows, so you can see what a complete report should contain. When you run a pentest on your own domain, you get a report in this same format, populated with your real findings, in hours.
Is the report acceptable for SOC 2 or a security questionnaire?
The report is built to meet the penetration testing documentation requirements of SOC 2, ISO 27001, HIPAA, and PCI DSS, and includes a signed attestation letter. It is the artifact customers and auditors ask for. Some framework scopes require manual testing; the compliance mapping document shows what is covered.
Get a report like this for your app
Enter your domain and get a full agentic AI pentest report in hours, from $99.
Run your pentest - $99 →