Coordinated and Responsible Vulnerability Disclosure Free Bug Bounty Program 327,488 coordinated disclosures
189,638 fixed vulnerabilities
398 bug bounties with 868 websites
9,147 researchers, 847 honor badges

  Please, login via Twitter first




Coordinated and Responsible Vulnerability Disclosure

Here you can submit a vulnerability via the Open Bug Bounty following coordinated and responsible disclosure:

Use only non-intrusive testing techniques that will not affect confidentiality, integrity or availability of the website, any related data or infrastructure.
Notify website owner in a prompt and reliable manner to help fixing the vulnerability, follow ISO 29147 guidelines of responsible disclosure.
Avoid reporting any vulnerabilities that will unlikely be fixed by the website owner.
Follow technical submission guidelines, otherwise submission may be declined.

Vulnerability Details

Vulnerability type:
* XSS URL:
POST data: appication/x-www-form-urlencoded
POST data example:


key1=value1&key2=value2
           
Cookies:
* CMS name:

Notifications

ISO 29147 Recommend Notification:
Notify subscribers:
A notification without technical details can be also sent to a specific security email you have for this submission. Please try to find the most appropriate one.
Send notification via twitter:
Automatic Disclosure:
 


  Latest Patched

 18.03.2019 byjus.com
 18.03.2019 twistys.com
 18.03.2019 bookboon.com
 18.03.2019 ucanr.edu
 18.03.2019 tampabay.com
 17.03.2019 russkoe.xxx
 16.03.2019 custojusto.pt
 15.03.2019 ilmattino.it
 15.03.2019 prisjakt.nu
 15.03.2019 newsone.ua

  Latest Blog Posts

24.02.2019 by ismailtsdln
Apple XSS Vulnerability - Proof of Concept (PoC)
24.02.2019 by ismailtsdln
How do you use an xss as a keylogger ?
23.02.2019 by ismailtsdln
Everything about XSS is in this source!
20.02.2019 by drok3r
ModSecurity - ByPass XSS
15.02.2019 by ismailtsdln
Adobe Israel Website XSS Vulnerability

  Recent Recommendations

    18 March, 2019
     DevTkd:
Thank you for your expressive vulnerability report. You do a great job. Thank you very much.
    15 March, 2019
     fkmclane:
Thanks for finding and responsibly reporting vulnerabilities in our websites and making them more secure!
    15 March, 2019
     despegar_appsec:
Nicholas found a vulnerability on one of our websites and responsibly reported it. Many thanks for letting us know.
    15 March, 2019
     stefan45863814:
Danke für den Hinweis, Armin. Es freut uns sehr, dass Du das Internet so tatkräftig zu einem besseren Ort machst.Stefan
    14 March, 2019
     CreditreformMGZ:
Lieber Armin, danke für die Meldung unserer Schwachstelle. Wir sind aktuell dabei Sicherheitslücken zu beheben - dein Hinweise hilft uns sehr dabei.