Finding Library
Manage a centralized repository of reusable vulnerability templates organized by category, shared across your organization.
The finding library is a centralized repository of vulnerability templates. Instead of writing the same finding from scratch on every engagement, build your library once and import findings into reports as needed.
How the Library Works
Your library contains two types of templates:
| Template Type | Visibility | Description |
|---|---|---|
| Global templates | All organizations | Shared by Vulnsy. A curated set of common vulnerability findings available to every workspace |
| Organization templates | Your workspace only | Custom findings created by your team. Private to your organization |
Browsing and Searching
From the Findings page, you can:
- Search by finding title using the search bar
- Filter by severity — show only Critical, High, Medium, Low, or Informational findings
- Filter by category — narrow results to Web App, Infrastructure, Mobile, Cloud, API, or IoT
Importing Findings into a Report
- Open a report and navigate to its findings section
- Click Add Finding
- Select Import from Library
- Search or browse for the finding you need
- Click to import it into the report
- Customize the imported finding for this specific engagement (adjust description, evidence, etc.)
Importing a finding creates a copy in the report. Changes you make to the imported finding only affect that report, not the original library template.
Managing Library Findings
Adding Findings
Create new library findings from the Findings page by clicking Add Finding and filling in the details. See Creating Findings for the full walkthrough.
Editing Findings
You can edit any organization template at any time. Update the title, severity, description, or any other field.
Editing a library finding does not retroactively update reports that already contain a copy of that finding. Each report holds its own independent copy from the moment of import.
Deleting Findings
Removing a finding from the library does not affect reports that have already imported it. The report copies are independent.
Building an Effective Library
- Start with the global templates provided by Vulnsy and customize them for your methodology
- After each engagement, save any new one-off findings to the library for future reuse
- Use consistent naming conventions so findings are easy to search (e.g. "SQL Injection — Login Form" rather than "SQLi issue")
- Keep descriptions generic enough to apply across clients, then customize per-report after importing