Our Security Community helped fix 36298 vulnerabilities

Report Email Alerts Open Bug Bounty: 107313 coordinated disclosures
Full Disclosure: 32316 vulnerabilities
Total Vulnerabilities Fixed: 36297
116264 vulnerable websites, 12669 VIP websites
2787 security researchers, 3863 notification subscribers

History of the Project

Initially known as XSSPosed, standing for 'XSS exposed', the OpenBugBounty project was created by security enthusiasts and professionals in June 2014. It was a non-profit open archive where any security researcher could report a Cross-Site Scripting (XSS) vulnerability on any website, and get a proper credit for it.

As many private Bug Bounty programs regularly fail these days, and the situation will unlikely improve in the near future, we decided that we need to create an open, transparent and unbiased platform to connect security researchers wishing to help and website administrators. This is how we created the concept of Open Bug Bounty Coordinated Vulnerability Disclosure Program that is currently open to everybody worldwide.

We have no financial or commercial interest in the project. Moreover, we pay hosting expenses and continuous web development from our pocket, and spend our nights verifying new submissions.

Open Bug Bounty: Public and Private

Security researcher can chose how to report the vulnerabilities via the Open Bug Bounty:

  • Public submission
    Once verified by our team, we send notifications, without disclosing any technical details of the vulnerability, to:

    • Subscribers (learn more)
    • Generic security emails
    • Emails found on the website (if any)
    • Emails provided by the researcher (if any)

    A web page dedicated to the vulnerability will be created, however no technical details will be displayed on it. At this stage, website owner, administrator or security company in charge of the website security shall contact the researcher directly and proceed to coordinated disclosure. Once patched, the vulnerability page may be deleted by researcher.

  • Private submission
    After verification by our team, the vulnerability will be available on a secret hyperlink known only to the researcher. The vulnerability is not used in any statistics or lists on the website. This is done to report vulnerabilities on websites running official bug bounty program, but refusing to reward researcher for hilarious reasons, like being unable to reproduce the vulnerability, or saying that the submission is a duplicate. Our independent and unbiased verification gives a clear prof that the vulnerability existed at a precise timestamp.

We always recommend website owners to thank responsible security researchers in a manner proportional to their time and efforts. However, our role is strictly limited to independent vulnerability verification - we never act as intermediary between the researchers and website owners.

Coordinated Disclosure and Notifications

We encourage all our security researchers to use the Open Bug Bounty program to report security vulnerabilities on websites without putting the website and its users at risk. However, its only the researcher who decides if he, or she, will use a coordinated or Full Disclosure.

In any case, we send security notifications to website owners by all available communication channels (including emails and social networks) to make sure that they are aware of the vulnerability and can patch it quickly.

Website owners and administrators can also subscribe for free instant alerts and get customized notifications about any vulnerabilities detected on their websites.

To avoid spam, we allow reporting only one vulnerability per domain per 24 hours. Every recipient of notifications sent can definitely unsubscribe from any further notifications.

Non-Intrusive Testing

We accept only the Cross-Site Scripting (XSS) and CSRF vulnerabilities that are the most common today.

The process of testing for XSS and CSRF is harmless and cannot damage the website, database, server or related infrastructure. We do not accept vulnerabilities that can, or are intended to, harm a website.

Privacy & Security

To avoid storing any user-related data, we use external authentication via Twitter for everyone on the website. Connection to the website is HTTPS only.

Researchers' Privileges

Within the scope of the Open Bug Bounty, solely security researchers can delete the vulnerabilities until public disclosure. However, they have absolutely no obligation to do so, and are free to act, or not to act, at their sole discretion. We never remove any information about vulnerabilities from the website for political or business reasons.

However, if researcher's behavior borders with extortion (e.g. demanding cash to delete a submission) - such submissions will be deleted - we have tolerance zero for blackmailing.

All our web server logs go directly to /dev/null, so don't even ask for them - we simply don't have them.

Latest VIP Submissions

activecampaign.com
Reported by dim0k Twitter: @d1m0ck
Recommendations received: 21
Approved XSS vulnerabilities: 4121
Approved XSS vulnerabilities on VIP websites: 2644
on 27.03.2017
runkeeper.com
Reported by dim0k Twitter: @d1m0ck
Recommendations received: 21
Approved XSS vulnerabilities: 4121
Approved XSS vulnerabilities on VIP websites: 2644
on 27.03.2017
dialog.ua
Reported by OmniGooch Recommendations received: 2
Approved XSS vulnerabilities: 2570
Approved XSS vulnerabilities on VIP websites: 149
on 26.03.2017
star.com.tr
Reported by porthunter Twitter: @porthunter
Recommendations received: 1
Approved XSS vulnerabilities: 301
Approved XSS vulnerabilities on VIP websites: 127
on 26.03.2017
3djuegos.com
Reported by porthunter Twitter: @porthunter
Recommendations received: 1
Approved XSS vulnerabilities: 301
Approved XSS vulnerabilities on VIP websites: 127
on 26.03.2017
laposte.fr
Reported by porthunter Twitter: @porthunter
Recommendations received: 1
Approved XSS vulnerabilities: 301
Approved XSS vulnerabilities on VIP websites: 127
on 26.03.2017
itu.int
Reported by Over Approved XSS vulnerabilities: 635
Approved XSS vulnerabilities on VIP websites: 145
on 26.03.2017
urlaubsguru.de
Reported by secuninja Recommendations received: 2
Approved XSS vulnerabilities: 136
Approved XSS vulnerabilities on VIP websites: 6
on 26.03.2017
wko.at
Reported by L1M4R Approved XSS vulnerabilities: 201
Approved XSS vulnerabilities on VIP websites: 2
on 26.03.2017
meinestadt.de
Reported by secuninja Recommendations received: 2
Approved XSS vulnerabilities: 136
Approved XSS vulnerabilities on VIP websites: 6
on 26.03.2017

Latest Submissions

handwerker-versand.de
Reported by badmaxx Twitter: @_badmaxx_
Approved XSS vulnerabilities: 76
on 27.03.2017
backformen-onlineshop.de
Reported by badmaxx Twitter: @_badmaxx_
Approved XSS vulnerabilities: 76
on 27.03.2017
wogibtswas.de
Reported by badmaxx Twitter: @_badmaxx_
Approved XSS vulnerabilities: 76
on 27.03.2017
backwelt24.de
Reported by badmaxx Twitter: @_badmaxx_
Approved XSS vulnerabilities: 76
on 27.03.2017
intergastro.de
Reported by badmaxx Twitter: @_badmaxx_
Approved XSS vulnerabilities: 76
on 27.03.2017
wasteskins.com
Reported by Spam404 Twitter: @Spam404Online
Recommendations received: 61
Approved XSS vulnerabilities: 21980
Approved XSS vulnerabilities on VIP websites: 1556
on 27.03.2017
smarthealthshop.com
Reported by OmniGooch Recommendations received: 2
Approved XSS vulnerabilities: 2570
Approved XSS vulnerabilities on VIP websites: 149
on 27.03.2017
meilleurmobile.com
Reported by Gr00v_ Twitter: @Gr00v_
Approved XSS vulnerabilities: 11
Approved XSS vulnerabilities on VIP websites: 8
on 27.03.2017
prix.net
Reported by Gr00v_ Twitter: @Gr00v_
Approved XSS vulnerabilities: 11
Approved XSS vulnerabilities on VIP websites: 8
on 27.03.2017
b-abo.ru
Reported by OmniGooch Recommendations received: 2
Approved XSS vulnerabilities: 2570
Approved XSS vulnerabilities on VIP websites: 149
on 26.03.2017