Sample A real Xalgorix report. Click any finding for full detail.

Run one on your target — from $1 →

Xalgorix · Offensive Security · Engine xalgo v1.4.2

Security Assessment Report

Prepared for
pentest ground
Target
https://pentest-ground.com:9000
Engagement mode
SINGLE
Assessment window
19 Jun 2026 · 17 min
Methodology
22-phase offensive workflow
Reference
7c447778

Overall risk rating

CRITICAL

One or more vulnerabilities pose immediate risk of compromise.

100 / 100

Severity distribution

The engine reported 9 verified findings 3 critical, 5 high, and 1 medium. Every finding was reproduced before inclusion.

critical
3
high
5
medium
1
low
0
info
0

Findings (9)

IDSeverityCVSSFinding
XALG-1critical9.8Remote Code Execution via Python Code Injection in /eval EndpointView →
XALG-2critical9.1OS Command Injection in /uptime/{flag} EndpointView →
XALG-3critical9.8SQL Injection with Full Database Dump — Plaintext Passwords ExposedView →
XALG-4high7.5Plaintext Password Storage in DatabaseView →
XALG-5high7.5XML External Entity (XXE) Injection in /search EndpointView →
XALG-7high7.5Plaintext Password Exposure in User Endpoint ResponseView →
XALG-8high7.5Token Expiration Not Enforced — Expired Tokens Remain ValidView →
XALG-9high7.5Authentication Token Exposed in Public HTML PageView →
XALG-6medium6.5Weak Token Generation Using MD5 HashView →

Get this for your own target

Your first scan is just $1 — it runs the full 22-phase pipeline and produces a branded PDF like this. Credits never expire.