Infosec Institute

Open Bug Bounty mentioned in the
Top 6 Bug Bounty programs of
2022 by the InfoSec Institute

The Hacker News

Open Bug Bounty named among the
Top 5 Bug Bounty programs of 2021
by The Hacker News

Platform update: please use our new authentication mechanism to securely use the Open Bug Bounty Platform.
For security researchers
Report a Vulnerability
Submit, help fixing, get kudos.
For website owners
Start a Bug Bounty
Run your bounty program for free.
1,712,057 coordinated disclosures
1,387,517 fixed vulnerabilities
2,003 bug bounty programs, 3,907 websites
47,911 researchers, 1,654 honor badges

Make web a safer place and become a cybersecurity hero.

Open Bug Bounty for Security Researchers

In order to report a vulnerability via Open Bug Bounty you should login first

  Latest Patched

 23.05.2024 nqheritage.jcu.edu.au
 23.05.2024 idd64.titan-man.me
 23.05.2024 idd34.titan-man.me
 22.05.2024 cdpc.sydney.edu.au
 22.05.2024 rsis.edu.sg
 22.05.2024 fesc.edu.co
 22.05.2024 ceza.gov.ph
 21.05.2024 expresscar.am
 21.05.2024 opera.am

  Latest Blog Posts

04.12.2023 by BAx99x
Unmasking the Power of Cross-Site Scripting (XSS): Types, Exploitation, Detection, and Tools
04.12.2023 by a13h1_
$1120: ATO Bug in Twitter’s
04.12.2023 by ClumsyLulz
How I found a Zero Day in W3 Schools
04.12.2023 by 24bkdoor
Hack the Web like a Pirate: Identifying Vulnerabilities with Style
04.12.2023 by 24bkdoor
Navigating the Bounty Seas with Open Bug Bounty

  Recent Recommendations

    22 May, 2024
    AndySchmidt:
Rajesh pointed out two different important vulnerabilities and supplied the necessary details for us to reproduce the issues. We appreciate his professionalism throughout the process.
    14 May, 2024
    TheDevinSwan:
Thank you for reporting vulnerabilities on our site. Your prompt assistance enabled us to resolve the issue quickly.
    1 May, 2024
    Mek:
Got a recommendation to fix an SQL injection vulnerability on my website. As I am a hobbyist and my page is a hobby project, I can't offer money, so I am recommending this researcher. Thanks again.
    26 April, 2024
    I_bims_Mike:
Thank you very much for identifying the XSS vulnerability and for our friendly email exchange.
    22 April, 2024
    genoverband:
Thank you for your invaluable help in ensuring the security of our domain and its visitors!