Documentation Index
Fetch the complete documentation index at: https://mintlify.com/simplevulnerabilitymanager/svm/llms.txt
Use this file to discover all available pages before exploring further.
Report Generation
Simple Vulnerability Manager enables you to generate professional, comprehensive security assessment reports in Microsoft Word format. The report generation system uses customizable templates and supports multiple report types with advanced formatting options.Overview
SVM’s reporting engine transforms your project data into polished Word documents:- Template-Based: Uses customizable Word templates (
.dotxformat) - Multiple Report Types: Technical, Executive, and Generic reports
- Automated Formatting: Applies styles, tables, and formatting automatically
- Variable Substitution: Dynamic content based on project data
- Statistical Graphics: Optional charts and graphs showing vulnerability distribution
- Risk-Based Styling: Different table styles for each risk level
Report Template
Template_SVM.dotx
The default Word template (Template_SVM.dotx) serves as the foundation for all generated reports. This template includes:
- Pre-defined heading styles
- Table formatting styles
- Document structure and layout
- Header and footer configurations
- Custom variables for dynamic content
Customizing the Template
Open Template for Editing
Modify Styles and Formatting
- Heading Styles: Configure Title, Heading 1, Heading 2, etc.
- Table Styles: Create custom table formats for vulnerability listings
- Colors and Fonts: Match your corporate identity
- Logo and Headers: Add company branding elements
- Page Layout: Margins, orientation, and page size
Configure Style Extraction
- Opens and reads the template file
- Extracts all heading style formats (Titulo_SVM, Heading 1, Heading 2, etc.)
- Extracts all table style formats
- Displays available styles in configuration interface
Template Variables
The template supports dynamic variables that are replaced with actual project data during report generation:Available Variables
Available Variables
[Proyecto]- Project name (can be used in vulnerability details since version 1.1.789)[Cliente]- Client name[Fecha]- Assessment date[Subtitulo]- Subtitle (replacement fixed in version 2.0.2)[Web]- Web addresses from project[IP]- IP addresses from project[Analista]- Analyst name[Empresa]- Company name
Using Variables in Templates
Using Variables in Templates
Report Types
SVM supports three types of security assessment reports:- Technical Report
- Executive Report
- Generic Report
- Detailed vulnerability descriptions
- Technical exploitation details
- Full request/response data
- Step-by-step remediation instructions
- Evidence screenshots with technical annotations
- CVSS scores and technical metrics
- Proof-of-concept demonstrations
Configuring Report Settings
Risk-Based Table Formatting
One of SVM’s most powerful features is the ability to apply different table styles based on vulnerability risk level:Select Template
.dotx file). SVM will automatically extract available styles.Assign Risk Colors
- Critical (default: Dark Red)
- High (default: Red)
- Medium (default: Orange)
- Low (default: Yellow)
- Informational (default: Blue)
Assign Table Styles
- Each risk level can have a different table style
- Styles are extracted from your Word template
- Allows visual differentiation in reports
- Creates professional, color-coded vulnerability tables
Configure Heading Styles
Statistical Graphics
Enabling Charts and Graphs
Enabling Charts and Graphs
- Vulnerability Count by Risk: Bar or pie charts showing risk distribution
- Vulnerability Types: Charts categorizing by vulnerability class
- Custom Colors: Graphics use your configured risk level colors
- Color Indicators: Preview your selected colors in configuration
Generating Reports
Report Generation Workflow
Complete Project Assessment
- All detected vulnerabilities
- Evidence screenshots for each finding
- Personalized comments and context
- Request/response data where applicable
- Project metadata (client, dates, scope)
Select Report Type
- Technical for security teams
- Executive for management
- Generic for mixed audiences
Configure Report Options
- Include/exclude statistical graphics
- Select which vulnerability categories to include
- Configure evidence placement
- Choose detail level
Generate Report
Report Structure
Generated reports follow this typical structure:- Cover Page: Project name, client, date
- Executive Summary: High-level findings and recommendations
- Scope and Methodology: Assessment details and approach
- Statistical Overview: Charts and graphs (if enabled)
- Vulnerability Findings: Detailed vulnerability listings by risk level
- Description
- Impact assessment
- Evidence (screenshots, request/response)
- Remediation steps
- Custom comments
- Conclusion and Recommendations: Summary and prioritized actions
- Appendices: Supporting documentation
Advanced Features
Evidence Placement
Screenshot and Evidence Handling
Screenshot and Evidence Handling
- Screenshots are inserted as images
- Maintains aspect ratio and reasonable sizing
- Caption with evidence description
- Request/response data in formatted code blocks
- Custom comments integrated into vulnerability description
Multi-language Reports
Language Support
Language Support
- Spanish: Original language, full support
- English: Complete translation of report elements
- Russian: Added in version 2.1.0
Temporary File Handling
Troubleshooting
Microsoft Word Not Installed
Microsoft Word Not Installed
Template Variable Not Replaced
Template Variable Not Replaced
Invalid Filename Error
Invalid Filename Error
<, >, :, ", /, \, |, ?, *). This validation was added in version 2.1.2. Rename your project to use only valid characters.Large Report Timeout
Large Report Timeout
Table Styles Not Applied
Table Styles Not Applied
- Ensure your Word template contains the table styles you’ve configured
- Re-extract styles by opening the template in Configuration
- Verify table style assignments match available styles in template
- Check template compatibility (Titulo_SVM style should be present for version 2.0.3+)
Excel Export Issues
Excel Export Issues
Report Quality Best Practices
Effective Report Writing
Effective Report Writing
- Complete Evidence: Include comprehensive screenshots and proof for each finding
- Clear Comments: Write clear, project-specific comments explaining impact
- Consistent Naming: Use consistent vulnerability names across projects
- Risk Accuracy: Assign appropriate risk levels based on actual impact
- Context Matters: Explain why each vulnerability matters to this specific client
- Remediation Focus: Provide actionable, specific remediation steps
- Professional Formatting: Use your customized template consistently
- Quality Review: Always review generated reports before delivery
Template Maintenance
Template Maintenance
- Regularly update branding and styling
- Test template with sample data before using in production
- Maintain backup copies of working templates
- Document custom variables and their usage
- Ensure compatibility with Word versions used by clients
- Use Titulo_SVM style for maximum compatibility
Export and Sharing
Report Formats
Generated reports are created as Word documents (.docx format):
- Can be converted to PDF for distribution
- Editable for final customization
- Compatible with Microsoft Word 2007 and later
- Can be shared via email or document management systems
Backup and Archiving
Related Documentation
- Project Management - Learn how to structure projects for reporting
- Vulnerability Database - Understand vulnerability categorization and details