Report a Vulnerability
Submit, help fixing, get kudos.
Start a Bug Bounty
Run your bounty program for free.
494,800 coordinated disclosures
269,945 fixed vulnerabilities
668 bug bounties with 1,349 websites
13,768 researchers, 1038 honor badges

Lidl Digital Bug Bounty Program

Lidl Digital runs a bug bounty program to ensure the highest security and privacy of its websites. Everyone is eligible to participate in the program subject to the below-mentioned conditions and requirements of Lidl Digital

Open Bug Bounty performs triage and verification of the submissions. However, we never intervene to the further process of vulnerability remediation and disclosure between Lidl Digital and researchers.

Bug bounty program allow private and public submissions.

Bug Bounty Scope

The following websites are within the scope of the program:

*.lidl-shop.sk
lidl-sklep.pl
lidlonline.es
*.lidl.de
*.lidl-shop.cz
*.lidl-shop.nl
*.lidl-shop.be

Non-Intrusive Submissions Handling

The following section encompasses submission of the vulnerabilities that do not require intrusive testing as per Open Bug Bounty rules:

- Cross Site Scripting (XSS)
- Open Redirect

- Cross Site Request Forgery (CSRF)
- Improper Access Control

General Requirements:

All kind of issues can be reported

Testing Requirements:

Dont use exessive brute force Scanners and dont fill out to many form fields, since it may create internal emails

Possible Awards:

nothing yet

Community Rating

Provided by security researchers who reported security vulnerabilities via this bug bounty program:

 
Response Time  How quickly researchers get responses to their submissions.
Remediation Time  How quickly reported submissions are fixed.
Cooperation and Respect  How fairly and respectfully researchers are being treated.

Researcher's comments

    6 December, 2019
    jub0bs:
I agree with Kenan. I've reported multiple vulnerabilities to Lidl in the past, and they made it clear to me that they don't give rewards, regardless of severity.
    30 October, 2019
    Kenan:
please remove this company from "bug bounty list", they don't have bug bounty, also as they promised they didn't reward

  Latest Patched

 27.01.2020 ytranking.net
 27.01.2020 zapmeta.com
 27.01.2020 insidesport.co
 27.01.2020 laist.com
 27.01.2020 laposte.fr
 27.01.2020 name.com
 27.01.2020 nsmall.com
 27.01.2020 harvard.edu
 27.01.2020 apkgk.com
 27.01.2020 fueleconomy.gov

  Latest Blog Posts

20.01.2020 by Rando02355205
XSS on "www.alibaba.com" (Alibaba WAF 405) Bypassed.
16.01.2020 by Open Bug Bounty
Brief Recap of Open Bug Bounty’s Record Growth in 2019
12.01.2020 by JCQ_47
WAF Cloudflare Bypass XSS at Nexusmods.com
08.01.2020 by devl00p
Top 100 Open Redirect dorks
08.01.2020 by Rando02355205
XSS WAF Bypassed

  Recent Recommendations

    27 January, 2020
     gaborvitez:
Helped us find and fix a cross site scripting vulnerability. He was very helpful and fast.
    27 January, 2020
     gaborvitez:
Found a cross site scripting vulnerability on our site, was very helpful with fast communication.
    27 January, 2020
     TristanGuiheux:
haxmov has helped us to find and fix some issues on web sites we're protecting. This kind of help is greatly appreciated from a security perspective. This way we can improve ourselves and protect our customers. Thanks again in my name.
    24 January, 2020
     2BeBetta:
Hi! Thanks for reporting an issue. It has been patched.
    24 January, 2020
     ryne70030772:
Thanks Again.