ISTQB Mock App

Common Vulnerability Scoring System

Common Vulnerability Scoring System (CVSS) is a standardized method for measuring the severity of software vulnerabilities.

Official definition
ISTQB Official Glossary Definition
A free and open industry standard for assessing the severity of system security vulnerabilities based on the ease and impact of an attack.

(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)

View the complete ISTQB Glossary

What is Common Vulnerability Scoring System?

CVSS assigns numerical scores based on factors such as exploitability and impact, helping organizations prioritize vulnerability remediation.

Severity scoring: Scores range from low to critical severity.

Risk prioritization: Higher scores generally require faster remediation.

Standardized approach: Enables consistent vulnerability evaluation.

Real World Example

A regulated product team is preparing a release where Common vulnerability scoring system appears in reviews, test design conversations, or defect triage rather than as an isolated glossary word.

The risk is that the team treats Common vulnerability scoring system as interchangeable with nearby ISTQB terms. That makes test scope blurry and can lead to weak evidence for the release decision.

The tester anchors the discussion in the official definition, asks where the concept appears in the product, and designs examples that show the difference between Common vulnerability scoring system and similar ideas.

The page becomes useful in practice because Common vulnerability scoring system is connected to a specific testing decision, not memorized as a detached definition.

Practice Questions

Question 1

Which statement is TRUE about CVSS?

Question 2

Why might two teams report different CVSS scores?

Test your knowledge with real ISTQB-style questions

You’ve learned Common Vulnerability Scoring System. Test your understanding with topic-specific questions in our Mock Exams.

Go to Mock Exams