Report Email Alerts Open Bug Bounty: 176,363 coordinated disclosures
Total Vulnerabilities Fixed: 78,557
167,744 vulnerable websites, 16,255 VIP websites
4,067 security researchers, 5,466 notification subscribers

Open Bug Bounty ID

OBB-293888

acorns.com Security Vulnerability

On the 13.09.2017 security researcher dim0k Helped patch 2943 vulnerabilities
Received 7 Coordinated Disclosure badges
Received 21 recommendations
disclosed XSS vulnerability affecting acorns.com website.

On our side, we have notified website owner via all reasonable communication channels about the vulnerability, so it can be patched as quickly as possible.

Currently the vulnerability is patched and does not represent any security risk for the website or its visitors.

Vulnerability Details


acorns.com Description

Acorns - Invest Spare Change | Acorns. Acorns automatically invests your spare change. Our mobile-first investment platform enables commission free investing, portfolio management with automatic .

Vulnerable URL:

Other details:

Patched:Yes, at 14.10.2017
Latest check for patch:14.10.2017 16:58 GMT
Vulnerability type:XSS
Vulnerability status:Publicly disclosed
Alexa Rank24307
VIP website status:Yes
Check acorns.com for malware:Click here
Check acorns.com SSL connection:Click here (Grade: A+) Refresh Results

Screenshot: acorns.com XSS vulnerability

Mirror: Click here to view the mirror

Coordinated Disclosure Timeline

Vulnerability submitted via Open Bug Bounty13 September, 2017 09:50 GMT
Generic security notifications sent to website owner13 September, 2017 09:52 GMT
Notification sent to subscribers (without technical details)13 September, 2017 10:17 GMT
Vulnerability details disclosed by researcher13 October, 2017 10:15 GMT
Vulnerability patched by the website owner15 October, 2017 09:21 GMT

User Comments:

Please login via twitter to be the first one to comment.


Latest Vulnerabilities on *.acorns.com

OBB-ID Reported by Status Reported on
On Hold
10.11.2017
patched
13.09.2017

Latest Vulnerabilities Reported by dim0k

OBB-ID Vulnerability Status Reported
On Hold
14.11.2017
On Hold
07.11.2017
On Hold
06.11.2017
On Hold
01.11.2017
On Hold
26.10.2017
On Hold
23.10.2017
On Hold
23.10.2017
On Hold
19.10.2017
On Hold
19.10.2017
On Hold
19.10.2017
On Hold
18.10.2017
On Hold
18.10.2017
On Hold
18.10.2017
On Hold
17.10.2017
On Hold
12.10.2017
On Hold
09.10.2017
patched
05.10.2017
patched
29.09.2017
On Hold
29.09.2017
On Hold
29.09.2017


LATEST VIP SUBMISSIONS

poradnikzdrowie.pl
Reported by OmniGooch Helped patch 1219 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 6 recommendations
on 18.11.2017
hawaii.edu
Reported by OmniGooch Helped patch 1219 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 6 recommendations
on 18.11.2017
kikocosmetics.com
Reported by OmniGooch Helped patch 1219 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 6 recommendations
on 18.11.2017
carters.com
Reported by OmniGooch Helped patch 1219 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 6 recommendations
on 18.11.2017
lotto24.de
Reported by amlnspqr Helped patch 937 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 10 recommendations
on 17.11.2017
cian.ru
Reported by eb Helped patch 639 vulnerabilities
Received 6 Coordinated Disclosure badges
Received 26 recommendations
on 17.11.2017
microstrategy.com
Reported by The_Pentester Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 17.11.2017
matchendirect.fr
Reported by SoKa Helped patch 10 vulnerabilities
Received 0 Coordinated Disclosure badges
on 17.11.2017
diablofans.com
Reported by sehno Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 17.11.2017
weddingwire.com
Reported by TAHA Helped patch 54 vulnerabilities
Received 2 Coordinated Disclosure badges
Received 10 recommendations
on 17.11.2017



LATEST SUBMISSIONS

dmf.go.th
Reported by OmniGooch Helped patch 1219 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 6 recommendations
on 18.11.2017
eeagrants.org
Reported by OmniGooch Helped patch 1219 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 6 recommendations
on 18.11.2017
bridgeresults.net
Reported by ut Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 18.11.2017
triangel.sk
Reported by OmniGooch Helped patch 1219 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 6 recommendations
on 18.11.2017
pccorner.com.ph
Reported by Gerardway Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 18.11.2017
swimrankings.net
Reported by ut Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 18.11.2017
jeseniky.net
Reported by ut Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 18.11.2017
mathcelebrity.com
Reported by Chris5389 Helped patch 14 vulnerabilities
Received 1 Coordinated Disclosure badges
on 18.11.2017
ieeesb.old.qut.ac.ir
Reported by Chris5389 Helped patch 14 vulnerabilities
Received 1 Coordinated Disclosure badges
on 18.11.2017
rentingcar.ir
Reported by Chris5389 Helped patch 14 vulnerabilities
Received 1 Coordinated Disclosure badges
on 18.11.2017