# Share an OpenVAS / Greenbone Report — Without Mailing the Host List

Canonical: https://commareports.com/share-openvas-report
Published: 2026-09-08

> Greenbone exports vulnerability reports as HTML, PDF or XML. Publish the HTML to Comma for a revocable URL with a thread per host instead of an attachment nobody can recall.

# Share an OpenVAS / Greenbone report

A Greenbone vulnerability scan produces the most operationally sensitive
document in a typical infrastructure team's year: every host it could reach,
every open port, every service version, and every known vulnerability against
them.

The export options are HTML, PDF, CSV and XML:

```
Scans → Reports → select the report → Download → Report format: HTML
```

And then it becomes an email attachment, or a file on a share drive, and stays
there — accurate for about a week, and permanently un-recallable.

## Filter before you export

The default full-and-fast configuration produces enormous reports, most of it
informational. A report that opens on 4,000 "Log" severity entries does not get
read past the first screen.

In the report view, filter to what somebody will act on:

```
severity>3.9 and apply_overrides=1 and rows=1000
```

That gives you medium and above, with your accepted-risk overrides applied, and
it usually reduces the report by an order of magnitude. Export *that* view —
Greenbone applies the active filter to the download.

## Publish it

Drag the exported HTML into [the app](https://commareports.com/), or POST it:

```bash
curl -fsS -X POST "https://commareports.com/api/v1/reports" \
  -H "Authorization: Bearer $COMMA_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d "$(jq -n --rawfile html openvas-report.html \
        --arg t "Greenbone — DMZ subnet, 2026-09-08" \
        '{title: $t, html: $html}')"
```

To do it from the scan job rather than by hand, pull the report over GMP first:

```bash
gvm-cli --gmp-username "$GVM_USER" --gmp-password "$GVM_PASS" \
  socket --xml "<get_reports report_id=\"$REPORT_UUID\" \
    format_id=\"6c248850-1f62-11e1-b082-406186ea4fc5\" \
    filter=\"severity&gt;3.9 apply_overrides=1\"/>" \
  | xmlstarlet sel -t -v '//report_format/../text()' | base64 -d > openvas-report.html
```

(`6c248850-…` is the built-in HTML report format id; confirm it against
`<get_report_formats/>` on your installation.)

## Set the access first

Reports are private by default, and this is a report type where that default is
load-bearing. It is an inventory of your internal estate and its weaknesses.

- **Team** access for the infrastructure group that owns remediation.
- **Named reviewers** when an auditor or a specific external party needs it.
- **Never public**, and think twice before domain-gated if the domain is large.

See the [sharing model](/docs/sharing).

## Scheduled scans, one URL

The point of a recurring scan is the trend, and the trend is invisible when
every run produces a new attachment. PATCH one report id per scan target:

```bash
curl -fsS -X PATCH "https://commareports.com/api/v1/reports/$REPORT_ID" \
  -H "Authorization: Bearer $COMMA_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d "$(jq -n --rawfile html openvas-report.html \
        --arg t "Greenbone — DMZ subnet, $(date +%F)" '{title: $t, html: $html}')"
```

One stable URL per subnet, one revision per scan. "Did the patch window
actually clear those?" becomes a comparison between two revisions rather than a
search through a mailbox.

## What review adds

- **Anchored threads** per host or finding, so "10.4.2.19 is decommissioned,
  ticket INF-882" is recorded where the finding is, not in a side channel.
- **Revisions**, which give you the remediation trend as evidence.
- **Revocable access**, so a contractor's view ends when the engagement does.

See [commenting on HTML](/comment-on-html).

## Limits

- **Entry HTML: 5 MB.** An unfiltered scan of a large network will exceed it —
  which is the same reason it would not be read. Filter by severity, or publish
  per-subnet reports.
- **60 requests/minute per token.**

## Try it

Comma is free — unlimited reports, unlimited commenters, unlimited revision
history.

**[Publish a scan privately →](https://commareports.com/)**

### Related

- [Share a Nmap report](/share-nmap-report) · [Share a Nikto report](/share-nikto-report)
- [Share a pentest report](/share-pentest-report) · [Share a Burp Suite report](/share-burp-suite-report)
- [Share a security scan report](/share-security-scan-report) · [Share a testssl report](/share-testssl-report)
