I performed an authorized penetration test on the Joss Shop web application using Burp Suite to analyze request/response traffic and identify security weaknesses. The assessment focused on input validation, session management, and common web vulnerabilities while operating strictly within the agreed scope. All findings were documented with severity ratings and practical remediation recommendations for the development team.