Vexta is VITI Security's agentless, AI-augmented vulnerability scanner and pentest platform, and its education module means every finding it reports answers the two questions a client, or a junior teammate, will actually ask: what is this, and why does it matter? Alongside plain-language answers to both, Vexta attaches the relevant CWE and OWASP references directly to the finding.
What does the education module actually add to a finding?
Three things, on every finding, regardless of severity: a plain-language answer to "What is this vulnerability?", a plain-language answer to "Why it matters", and the CWE and OWASP references that classify it. None of that lives in a separate manual you have to go dig up. It sits on the finding itself, next to the technical detail and the proof status, so the context is there the moment someone opens the finding rather than something they have to go find.
Who is this actually for, the hunter or the client?
Both, for different reasons. An experienced pentester does not need to be told what SQL injection is. What they do need is to not spend twenty minutes writing a client-friendly explanation of it from scratch for the fifth report this month, and the education module already has that written in a consistent, reusable form attached to the finding. A junior analyst on the same team gets something different from it: a fast, correct answer to "why does this matter" that they can build on instead of guessing at, or interrupting someone senior to ask.
On the client side, the person reading a report is often not the engineer who was on the call when the finding was walked through live. Weeks later, an engineering lead or a compliance reviewer opens the PDF cold, and the what-is-this and why-it-matters framing is what lets that finding stand on its own instead of depending on someone remembering the conversation.
How do the CWE and OWASP references fit into the bigger picture?
CWE and OWASP are the shared vocabulary that a finding needs to speak if it is going to connect to anything downstream: a client's own risk register, a security team's internal tracking, or a compliance review. Vexta also offers separate compliance reporting, mapping findings to frameworks like the OWASP Top 10, NIST 800-53, PCI-DSS and SOC 2 (see plans on the pricing page for what is included). The CWE and OWASP references baked into every finding's education content are the same standards vocabulary that kind of mapping relies on, so a finding is already speaking the language a compliance reviewer expects, rather than needing translation after the fact.
What does this look like day to day, during triage?
Triage is usually the least glamorous part of a scan and the part where explanatory context earns its keep the most. A hunter working through a long finding list does not want to stop and second-guess whether a given class of bug is worth escalating, especially on a class they have not seen in a while, or one a teammate flagged and asked them to review. Having the what-is-this and why-it-matters answer sitting on the finding itself means that judgment call takes seconds instead of a side trip to search documentation or ask around.
It also helps a team stay consistent. Two different testers writing up the same vulnerability class from memory will often phrase the risk differently, one might undersell it, another might overstate it. When the explanation comes from the finding itself instead of whoever happened to write that section of the report, a client reading two different reports from the same firm sees the same framing for the same class of bug both times.
Does this content carry through into the final report?
Because the what-is-this, why-it-matters and CWE/OWASP content lives on the finding itself, it carries straight through into Vexta's HTML, PDF and Word report exports, including the executive summary a client-side stakeholder is likely to read first. That matters in practice more than it sounds: an executive summary is usually the one part of a pentest report that gets read by someone without a security background, and having plain-language context already attached to the underlying findings means the summary is not the only place that context exists.
Key takeaways
- Every Vexta finding includes a plain-language "What is this vulnerability?" answer, a "Why it matters" answer, and CWE/OWASP references.
- This content is attached directly to the finding, not kept in a separate reference document.
- It saves an experienced hunter time on report writing and gives a junior analyst a reliable starting point.
- The same CWE/OWASP vocabulary used here is what Vexta's separate compliance framework mapping relies on.
- Education content carries through into Vexta's HTML, PDF and Word reports, including the executive summary.
Frequently asked questions
What does Vexta's education module include for each finding?
Is the education module only useful for junior analysts?
Do the CWE and OWASP references appear in client-facing reports?
Is the education content the same as Vexta's compliance framework mapping?
Does the education module depend on Vexta's AI triage being turned on?
See a finding that explains itself
Run a Vexta scan and see what-is-this, why-it-matters context attached to every finding, not just a severity label.

