Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
vulnrepo — VULNRΞPO - Free vulnerability report generator and repository, end-to-end encrypted! Templates of issues, CWE,CVE,MITRE ATT&CK,PCI DSS, import Nmap/Nessus/Burp/OpenVAS/Bugcrowd/Trivy, Jira export, TXT/JSON/MARKDOWN/HTML/DOCX, attachments, automatic changelog, stats, vulnerability management, bugbounty, local ai/llm, super fast pentest reporting! | Kitploit
Tools/GitHubGitHub/kac89/vulnrepo
Vulnerability ScannersEncryption/Decryption ToolsVulnerability AnalysisPenetration TestingLearning & EducationCurated ResourcesAI Security
GitHubkac89/vulnrepo

vulnrepo

View Repository
5701186616h 45m agoReviewed by Kitploit
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

VULNRΞPO - Free vulnerability report generator and repository, end-to-end encrypted! Templates of issues, CWE,CVE,MITRE ATT&CK,PCI DSS, import Nmap/Nessus/Burp/OpenVAS/Bugcrowd/Trivy, Jira export, TXT/JSON/MARKDOWN/HTML/DOCX, attachments, automatic changelog, stats, vulnerability management, bugbounty, local ai/llm, super fast pentest reporting!

Share

VULNRΞPO - Vulnerability Report Generator & Repository

License Angular Live App Docker

A client-side, privacy-first vulnerability report manager for security professionals. All data is encrypted and stored locally in your browser — nothing is sent to any server by default.

Live app: https://vulnrepo.com/ | Dev branch: https://dev.vulnrepo.com/

Video walkthrough / Tutorial:

Guide


Table of Contents

  • Features
  • Security Model
  • Supported Import Sources
  • Report Export Formats
  • Methodology Tools
  • AI / LLM Integration
  • Getting Started
    • Prerequisites
    • Development Server
    • Production Build
    • Docker
  • Project Structure
  • API Integration
  • Browser Support
  • Contributing
  • License

Features

  • Client-side encryption — reports are encrypted in the browser before storage; no backend required
  • Issue templates — create and reuse custom vulnerability templates; import from CVE, CWE, MITRE ATT&CK, and PCI DSS
  • Scanner imports — import findings directly from popular security tools (see Supported Import Sources)
  • Multiple export formats — TXT, HTML, DOCX; generate PDF via browser print
  • Encrypted HTML export — share an AES-encrypted, self-contained HTML report
  • File attachments — attach screenshots, tool output, or any file; SHA-256 checksum is computed automatically
  • Changelog — all significant report changes are versioned and logged automatically
  • Issue export — export issues to Atlassian Jira or as a portable encrypted file
  • Report sharing — share a full encrypted report with collaborators
  • Report profiles — save reusable report configurations (logo, researcher info, theme, CSS)
  • Template customization — edit the HTML report template and CSS directly in the app
  • Methodology tools — built-in checklists for OWASP ASVS 4, PCI DSS 4, and The Bug Hunter's Methodology (TBHM)
  • CVE search — query the NIST NVD database and pull CVE details into your report
  • Report history — automatic versioned snapshots of every save
  • Issue merge — merge duplicate or related issues
  • Advanced filter — filter and search issues by severity, status, tags, CVE, CVSS, and more
  • Bug bounty list — reference list of bug bounty programs
  • AI / LLM integration — connect a local Ollama model for AI-assisted report writing (see AI / LLM Integration)
  • Optional backend — store encrypted reports on your own server via the REST API (see API Integration)

Security Model

VULNRΞPO uses browser-native cryptography exclusively:

PropertyValue
Key derivationPBKDF2-SHA-256, 600,000 iterations
EncryptionAES-256-GCM (authenticated encryption)
Salt16 bytes, random per encryption
IV12 bytes, random per encryption
Encrypted data storageBrowser IndexedDB (local machine only by default)
Decryption key storageIn-memory only — never written to sessionStorage, localStorage, or any persistent medium
NetworkNo data leaves the browser unless you configure the optional API backend

Key lifetime and auto-lock

Decryption passwords are held in a short-lived in-memory vault (KeyVaultService) that is cleared automatically when any of the following occur:

  • Tab hidden — the browser tab loses focus or is switched away from (visibilitychange event)
  • Tab closed / page reload — pagehide and beforeunload events
  • Inactivity — 15 minutes of no keyboard, mouse, or touch input

After the vault is cleared, re-opening a report prompts for the password again. No key material is ever written to sessionStorage, localStorage, cookies, or any other persistent browser storage.

Reports encrypted with older versions of the app (legacy CryptoJS AES format) are automatically detected and decrypted for backward compatibility.

Important: There is no server-side key recovery. If you lose your security key, the report data cannot be recovered.


Supported Import Sources

ToolFormat
VULNRΞPO Encrypted.VULNR
VULNRΞPO Decrypted Issues.JSON
Burp Suite.XML
Bugcrowd.CSV
Nmap.XML
OpenVAS 9.XML
Tenable Nessus.NESSUS, .CSV
Trivy.JSON
Atlassian Jira.XML
NPM Audit.JSON
Semgrep.JSON
PHP Composer Audit.JSON
WIZ Issues.CSV
OWASP ZAP.JSON
BlackDuck Code Sight.JSON

Report Export Formats

FormatNotes
HTMLFully self-contained; customizable template and CSS
Encrypted HTMLAES-encrypted, self-contained HTML; share safely via email or file transfer
DOCXMicrosoft Word compatible
TXTPlain text
PDFUse browser Print to PDF (Ctrl+P) on the HTML export; or use the LaTeX generator for full customization

Methodology Tools

The following interactive checklists are available from the sidebar:

  • OWASP ASVS 4 — Application Security Verification Standard
  • PCI DSS 4 — Payment Card Industry Data Security Standard
  • TBHM — The Bug Hunter's Methodology

Use them during an assessment to ensure nothing is missed before finalizing the report.


AI / LLM Integration

VULNRΞPO integrates with Ollama to provide AI-assisted report writing using a locally hosted model. No data is sent to any cloud service.

Setup:

  1. Install Ollama from ollama.com.
  2. Pull and run a model:
    ollama run llama3.2:latest
    
  3. Allow the VULNRΞPO origin to access Ollama. If using the hosted app, set the environment variable before starting Ollama:
    OLLAMA_ORIGINS=https://vulnrepo.com ollama serve
    
  4. In VULNRΞPO, open AI Settings (robot icon in the report toolbar), enter your Ollama URL (http://localhost:11434 by default), select a model, and save.

Getting Started

Prerequisites

  • Node.js 18 or later
  • Angular CLI 22:
    npm install -g @angular/cli
    

Development Server

# Install dependencies
npm install

# Start the dev server
npm start
# or
ng serve

Navigate to http://localhost:4200/. The application reloads automatically when source files change.

Production Build

ng build -c production

Build artifacts are written to dist/vulnrepo-app/. Deploy the contents of that directory to any static web host or CDN.

Docker

The official Docker image is available on Docker Hub:

docker pull kac89/vulnrepo
docker run -p 8080:80 kac89/vulnrepo

See the image page for full documentation: https://hub.docker.com/r/kac89/vulnrepo


Project Structure

Download Tool