Skip to main content
CVSS 4.0

All audiences: Learn how CVSS 4.0 impacts severity

Updated today

HackerOne supports scoring severities for reports using a CVSS 4.0 calculator. CVSS, or the Common Vulnerability Scoring System, is an industry-standard calculator used to determine the severity of a vulnerability. The standard enables a common language around the severity of vulnerabilities. Learn more about CVSS 4.0.

HackerOne’s implementation of CVSS 3.0 and CVSS 3.1 supports environmental metric modifiers. This is no longer supported in CVSS 4.0 since this version has base metrics for Vulnerable System Impact and Subsequent System Impact Metrics.

Severity Caps

The affected asset in the report may have a maximum severity. In this case, the calculator will automatically cap the score and severity rating. The presence of a maximum severity will be indicated in the severity calculator.

Learn more about CVSS and Severity in our Severity document.

Did this answer your question?