forumNew topic

The end of the penetration test report had a 'high' risk flag — how serious is this?

RRecep K***MemberCommunity member
Joined
Apr 2022
Message
6
#1

I got the penetration test report yesterday. Got confused trying to read it. Some vulnerabilities are marked 'Low', some 'Medium', and at the end there are two 'High' risks.

For example, one says 'SQL injection possible', the other 'outdated SSL version'. One looks very serious but both are marked as the same 'high' risk. How many vulnerabilities do i need to fix?

I sent it to the developer and we're arguing about 'what does this mean'. One says 'it's not serious' the other says 'shut down the site'. How should i interpret the report?

ÜÜlkü Ç***Member
Job title
Technical service technician
Sector
Jewelry
Organization type
120-person company
Joined
Dec 2025
Message
336
Most Helpful#2

Risk rating is based on the CVSS standard. 'High' risk means that if the vulnerability is exploited, it could lead to serious damage.

SQL Injection: The entire database can be compromised, customer data can be stolen — definitely High. Old SSL version: encrypted connection might be weak, still needs to be fixed.

Priority: 1) All High risks ASAP, 2) Medium risks — within 1 month, 3) Low risks — add to backlog.

SSenaMember
Job title
Graphic Designer
Organization type
two-branch business
Joined
Jul 2024
Message
86
#3

sql injection is a big deal connection encryption etc and like counts as low. if it were me i'd fix the high risks this week

HHilal Y***Expert
Job title
Accounting Manager
Sector
Catering
Organization type
chain store
Joined
Aug 2025
Message
66
#4

Your report has an 'executive summary' page. At the top of the page, it lists how many High and how many Medium. Start there.

BBarış S***MemberCommunity member
Joined
Mar 2023
Message
79
#5

Some firms artificially inflate risk scores to jack up the 're-test' fee. If it says SQL injection, open the code and check if it's actually there or not.

SSinan T***MemberCommunity member
Joined
Sep 2025
Message
12
#6

so should i not fix all risks immediately, or are high risks enough?

TTaner A***Veteran
Job title
Intern
Sector
Advertising and promotion
Organization type
two-branch business
Joined
Mar 2025
Message
406
#7

Within the risk management framework, closing vulnerabilities rated as High is a legal compliance requirement. Even if you have a cyber insurance policy, coverage may be voided if you fail to close vulnerabilities you were explicitly warned about.

SSılaMember
Job title
Marketplace specialist
Organization type
8-person team
Joined
Mar 2024
Message
138
#8

The opposite happened to me, that's why I'm writing. Hasty decisions become decisions you have to fix six months later.

Good luck with that.

AAhmet A***MemberCommunity member
Joined
Oct 2023
Message
63
#9

I went through the same thing two years ago. If you scold false alarms, nobody will report again.

That's all, sorry if I went on too long.

TTuğçe K***Member
Job title
Warehouse Manager
Sector
Media and publishing
Organization type
40-person manufacturing company
Joined
Jan 2022
Message
5

Doki · Log management setup · 2024

#10

I went through the same thing two years ago. Processes without records never improve, because you don't know what to fix.

Proven by experience.

LLeyla Y***ExpertCommunity member
Joined
May 2025
Message
102
#11

I agree.

TTaner N***MemberCommunity member
Joined
Dec 2025
Message
13
#12

Three different views emerged, they all complement each other. Most time waste accumulates in tasks waiting for approval.

If I were you, I'd go this route.

OOya K***ExpertCommunity member
Joined
Jun 2024
Message
96
#13

let me summarize what's been said so far then just becasue everyone does it doesn't mean it's right.

good luck with that.

AAleyna E***MemberCommunity member
Joined
Aug 2024
Message
80
#14

I didn't know that.

RRamazan K***MemberCommunity member
Joined
Jul 2023
Message
102
#15

Following.

UUfuk A***ExpertCommunity member
Joined
Dec 2024
Message
410
#16

Thanks, that was the answer I was looking for.

İİbrahim K***MemberCommunity member
Joined
Mar 2026
Message
4
#17

Timely topic.

ZZeynep K***Member
Job title
Production Manager
Sector
IT services
Organization type
regional distributor
Joined
Feb 2025
Message
143

Doki · Interface design · 2026

#18

Thanks a lot, I'll try it today.

NNeslihan Y***Member
Job title
Social media manager
Sector
Advertising and promotion
Organization type
family business
Joined
Oct 2024
Message
307
#19

We experienced almost the exact same thing last year. Taking notes for two weeks yields better results than a six-month estimate.

Solutions that work at a small scale collapse when you grow; I learned this late. Hope this helps.

FFurkan M***Member
Job title
Product Manager
Sector
Construction
Organization type
medium-sized business
Joined
Dec 2024
Message
20
#20

noted, thanks.

Reply