Coordinated Disclosure Verified Alerts 229,678 coordinated disclosures
122,439 fixed vulnerabilities
185,478 websites, 16,786 VIP websites
6,198 researchers, 6,915 subscribers

  Please, login via Twitter first




Start Your Bug Bounty Program at Open Bug Bounty

Open Bug Bounty allows any verified website owners to run a bug bounty for their websites at no cost. The purpose of this non-profit activity is to make relations between website owners and security researchers sustainable and mutually beneficial in a long-term prospective.

Starting a bug bounty is free and open to everyone. Once logged in via Twitter, you can create your bug bounty program in a few minutes and get unlimited access to our security researchers. Once a vulnerability is reported, you will get instant notification to coordinate disclosure and remediation with researcher.

Open Bug Bounty does triage and verification of the submissions. However, we never intervene to the further process of your communication with the researchers, vulnerability remediation and disclosure. Once a vulnerability is verified and reported to you, our role in coordinated disclosure process is over.

General

Please carefully fill-in the form below to launch your bug bounty:

This will be a name under which your bug bounty will be displayed. Please use meaningful and relevant name to better guide the researchers.

Please read about type of vulnerability submissions and select the best one for you:

   Researchers will be able to submit both private and public submissions.
   Researchers will be able to submit private submissions only.

We will send notifications for domains from your scope to these email addresses. We do not share these email addresses with anybody.

Bug Bounty Scope

You will need to confirm your ownership of the website by placing a special security.txt file on it:

Non-Intrusive Submissions Handling

The following section encompasses submission of the vulnerabilities that do not require intrusive testing as per Open Bug Bounty rules:

- Cross Site Scripting (XSS)
- Open Redirect

- Cross Site Request Forgery (CSRF)
- Improper Access Control

Please specify your Vulnerability Disclosure Program requirements. They will be displayed to security researchers:

Please specify technical or any other reasonable requirements for submissions (e.g. exclusion of self-XSS). Please specify any special requirements for testing methodologies (e.g. restriction to use vulnerability scanners). Please specify which rewards you may provide to the researchers who follow the above-mentioned requirements (e.g. recommendation in researcher's profile, mention in a Hall of Fame or something more valuable proportional to the researcher's efforts). Anything else you would like to bring to the attention of researchers community.

Other Submissions Handling

Open Bug Bounty does not accept security vulnerabilities that may require some sort of intrusive testing to be detected (e.g. SQL injection). Therefore, we do not accept, verify or store them on our platform. Nevertheless, as a website owner, you can specify how and where to report them if ever you wish them to be reported.



Please specify where and how (e.g. email) these vulnerabilities may be sent. You can provide your public PGP key here to encrypt the notifications sent via a method you specify above. Please specify technical or any other reasonable requirements for submissions (e.g. exclusion of self-XSS). Please specify any special requirements for testing methodologies (e.g. restriction to use vulnerability scanners). Please specify which rewards you may provide to the researchers who follow the above-mentioned requirements (e.g. recommendation in researcher's profile, mention in a Hall of Fame or something more valuable proportional to the researcher's efforts). Anything else you would like to bring to the attention of researchers community.

Need Any Help?

Need any help or have any questions about the bug bounty? The community forum is here to help!



  Latest VIP Submissions

tour.ne.jp
Reported by metamorfosec Helped patch 26 vulnerabilities
Received 2 Coordinated Disclosure badges
Received 3 recommendations
on 21.06.2018
thepetitionsite.com
Reported by OmniGooch Helped patch 2224 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 8 recommendations
on 21.06.2018
allposters.com
Reported by OmniGooch Helped patch 2224 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 8 recommendations
on 21.06.2018
netsarang.com
Reported by ELProfesor Helped patch 748 vulnerabilities
Received 6 Coordinated Disclosure badges
Received 36 recommendations
on 20.06.2018
massaget.kz
Reported by ELProfesor Helped patch 748 vulnerabilities
Received 6 Coordinated Disclosure badges
Received 36 recommendations
on 20.06.2018
gurufocus.com
Reported by ELProfesor Helped patch 748 vulnerabilities
Received 6 Coordinated Disclosure badges
Received 36 recommendations
on 20.06.2018
onlineserieswatch.com
Reported by ELProfesor Helped patch 748 vulnerabilities
Received 6 Coordinated Disclosure badges
Received 36 recommendations
on 20.06.2018
hoc24.vn
Reported by ELProfesor Helped patch 748 vulnerabilities
Received 6 Coordinated Disclosure badges
Received 36 recommendations
on 20.06.2018
freeadult.games
Reported by ELProfesor Helped patch 748 vulnerabilities
Received 6 Coordinated Disclosure badges
Received 36 recommendations
on 20.06.2018
movie-wiki.net
Reported by ELProfesor Helped patch 748 vulnerabilities
Received 6 Coordinated Disclosure badges
Received 36 recommendations
on 20.06.2018



  Latest Submissions

gacc.nifc.gov
Reported by Cyberanteater Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 21.06.2018
galleryjapan.com
Reported by metamorfosec Helped patch 26 vulnerabilities
Received 2 Coordinated Disclosure badges
Received 3 recommendations
on 21.06.2018
freetradeireland.ie
Reported by malwrforensics Helped patch 33 vulnerabilities
Received 1 Coordinated Disclosure badges
on 21.06.2018
gmstudios.de
Reported by SecuNinja Helped patch 1595 vulnerabilities
Received 11 Coordinated Disclosure badges
Received 54 recommendations
on 21.06.2018
publica.upc.edu
Reported by metamorfosec Helped patch 26 vulnerabilities
Received 2 Coordinated Disclosure badges
Received 3 recommendations
on 21.06.2018
asprocergs.com.br
Reported by JVZI07 Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 21.06.2018
www4.sisproasp.com.br
Reported by JVZI07 Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 21.06.2018
cursovirtual.fundacaounimed.org.br
Reported by JVZI07 Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 21.06.2018
kagi.net
Reported by metamorfosec Helped patch 26 vulnerabilities
Received 2 Coordinated Disclosure badges
Received 3 recommendations
on 21.06.2018
touroperator.com.br
Reported by JVZI07 Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 21.06.2018