Infosec Institute

Open Bug Bounty mentioned in the
Top 6 Bug Bounty programs of
2022 by the InfoSec Institute

The Hacker News

Open Bug Bounty named among the
Top 5 Bug Bounty programs of 2021
by The Hacker News

Platform update: please use our new authentication mechanism to securely use the Open Bug Bounty Platform.
For security researchers
Report a Vulnerability
Submit, help fixing, get kudos.
For website owners
Start a Bug Bounty
Run your bounty program for free.
1,704,055 coordinated disclosures
1,383,027 fixed vulnerabilities
1,991 bug bounty programs, 3,919 websites
46,951 researchers, 1,651 honor badges

rajesh_appsec | Security Researcher Profile


Security researcher rajesh_appsec has already helped fix 484 vulnerabilities.



Researcher reputation:  860

Real name:
Rajesh Tewari

Contact email:
[email protected]

Alternative Contacts:
8197644455

Certifications & Diplomas:
CompTIA Security
CEH

Experience in Application Security
over 5 years

Award / Bug Bounty I prefer:
Bug Bounty Payments, Paypal, Swags, T-Shirt, Hall Of Fame

Recommendations and Acknowledgements | Full List:

@testmynet     2 October, 2020
    Twitter testmynet Damon from TestMy.net:
Rajesh has helped me find vulnerabilities multiple times even after knowing I don't have a bounty. Very cool. Thank you for taking the time to make our internet better.
@redicius     25 February, 2019
    Twitter redicius Pavel from vestirna.com:
Did find a XSS hole, shared it with me via openbugbounty. Did not try to blackmail me. Nice guy.
@novelgames     24 February, 2024
    Twitter novelgames Peter Lee from Novel Games Limited:
Reported an XSS vulnerability in our website.
@creality     22 November, 2023
    Twitter creality Developer from CQ:
Rajesh identified an XSS vulnerability on our site which could be fixed fast. Thanks for the provided information!
@Bibi     24 July, 2023
    Twitter Bibi Christoph from ARRAS@online:
Rajesh, thank you very much for informing me with a detailed report of security vulnerabilities in my websites.
@Delingsdorf     20 July, 2023
    Twitter Delingsdorf Stecki from Delingsdorf:
Rajesh was very helpful in pointing out and helping to fix some issues on our site. The help was very appreciated!
@DeshimaSounds     23 June, 2023
    Twitter DeshimaSounds SuperEuroJimmy from Eurobeat-Prime:
Rajesh found a XSS vulnerability on our website that we could fix using his feedback. Thanks a lot!!
@MikaHdzCusters     21 June, 2023
    Twitter MikaHdzCusters Mikael from NousProperty:
I am thrilled to share that, with Rajesh's invaluable assistance, I successfully resolved 10 XSS errors in just one day. Rajesh's expertise and dedication in cybersecurity were instrumental in addressing these vulnerabilities promptly and effectively. Their clear explanations and willingness to share knowledge made the process a valuable learning experience. I am sincerely grateful for Rajesh's support and professionalism in ensuring the security of our systems. I highly recommend Rajesh's services for any cybersecurity needs.

Mikael
@testmynet     10 May, 2023
    Twitter testmynet Damon from TestMy.net:
Rajesh is amazing, his vulnerability reports are top notch and help to reproduce and resolve issues quickly.

Thank you again for making our internet better!
@Freedback_com     9 May, 2023
    Twitter Freedback_com Steve from Freedback.com:
Rajesh found an XSS vulnerability in a part of my site that must have taken some time to find. Thank you!
@pagecp31     17 March, 2023
    Twitter pagecp31 Christian from Personal:
Huge thanks to Rajesh for pointing out an XSS vulnerability that affected several pages in the website I am developing on my free time. It is much appreciated and the report was very clear!
@benschrijver     7 February, 2023
    Twitter benschrijver Ben from A:
Rajesh pointed out several XSS issues with our application and offered helpful pointers to resolve them.
@rinconensalza     7 February, 2023
    Twitter rinconensalza Carlos from Ensalza:
Thank you for helping me to find some bugs on my web, very appreciated!!
@kaszko     12 December, 2022
    Twitter kaszko Kolos from BudapestHungary:
Rajesh provided detailed information and payload/examples to reproduce the vulnerabilities he discovered. He responded to my questions quickly and validated the fix. 10/10 would recommend. I appreciate his great effort.
@routhinator     14 November, 2022
    Twitter routhinator Chris Routh from The Den of Amateur Writing:
Thank you for your responsible disclosure of several XSS attacks against The Den. This signalled that I had missed an update to the CMS and once patched they were resolved.
@ThomasDBending     31 July, 2022
    Twitter ThomasDBending Thomas Bending from Thomas Bending:
Thank you for finding an XSS vulnerability in my website.
@madmas     30 June, 2022
    Twitter madmas Markus from Ev. Kirchengemeinde:
Thanks to Rajesh very detailed and useful reports, we could close some very important vulnerabilities in our system. Thank you!
@WebtunGrafix     28 March, 2022
    Twitter WebtunGrafix Thomas from Webtun Grafix:
Thank you Rajesh, for finding an XSS vulnerability on our website!
@Seywald     24 February, 2022
    Twitter Seywald W.Seywald from TSP:
Many thanks Rajesh for pointing out the XSS vulnerability on our website! We appreciate your help! It was a pleasure for us to work together.
@smiteworks     11 January, 2022
    Twitter smiteworks Doug D from SmiteWorks USA LLC:
Rajesh provided additional information to further strengthen our site. He is an asset to the online community.
@darione90     15 November, 2021
    Twitter darione90 Dario from Schiaparelli:
Thanks for helping us secure our website!
@EreMaijala     24 August, 2021
    Twitter EreMaijala Ere Maijala from The National Library of Finland:
Thank you for a responsible disclosure of a vulnerability! We appreciate the fast response to a details request.
@darione90     17 June, 2021
    Twitter darione90 Dario from Società Astronomica G.V. Schiaparelli:
Thanks a lot for finding an XSS vulnerability on our website!
@SBugreports     25 May, 2021
    Twitter SBugreports Spark Bug Reports from Spark NZ:
Thanks to Rajesh for reporting the vulnerabilities with our site. It has been a pleasure to deal with you.
@Dawn91571907     24 May, 2021
    Twitter Dawn91571907 anonymous from undercover:
Thank you very much Rajesh for the detailed report on the vulnerability of our website, we patched the vulnerability in time
@tugozevents     17 May, 2021
    Twitter tugozevents Team Tugoz from Tugoz LLC:
Thanks a lot, Rajesh, for taking time to test our product and for the detailed reporting of the vulnerabilities. It was a great experience working with you.
@smiteworks     15 January, 2021
    Twitter smiteworks Doug D from SmiteWorks USA LLC:
Rajesh was very helpful in providing information and penetration testing on our site. With this information, we were able to harden our infrastructure.
@syysvirta     17 December, 2020
    Twitter syysvirta Joonas from Anders:
Thank you Rajesh for reporting a vulnerability, sharing detailed additional information and thus helping us to patch it quickly. Keep up the good work!
@Ryte_CERT     16 November, 2020
    Twitter Ryte_CERT Armin from Ryte:
Thank you Rajesh for reporting vulnerabilities on our website, your quick and detailed response was very valuable to us!
@SNTech2     16 November, 2020
    Twitter SNTech2 Steve from Sharenet:
Thank you for reporting the vulnerabilities on our website, we appreciate the quick and detailed responses. Keep up the good work!
@lansewudao     28 October, 2020
    Twitter lansewudao Jin Lu from Talroo:
Thank you for finding the bug, Rajesh! We fixed it.
@Timeweb     27 October, 2020
    Twitter Timeweb Roman from Timeweb:
Thank you Rajesh for reporting vulnerabilities on our website, your quick and detailed response was very valuable to us!
@ferulasdentales     22 September, 2020
    Twitter ferulasdentales Staff FD :
Thanks a lot Rajesh for provide us all the vulnerability details in order to patch it, and also for the quick responses and your maximum collaboration.
@rundumsbaby     4 September, 2020
    Twitter rundumsbaby rundumsbaby from rundumsbaby:
Thank you very much for the reports. Excellent reports with a lot of details about the vulnerabilities and suggestions for fixing it.
@SNTech2     21 August, 2020
    Twitter SNTech2 Steve from Sharenet:
A big thank you for notifying us of the vulnerability and providing us with excellent details allowing us to quickly patch it. Keep up the great work!
@www_aasv_org     12 August, 2020
    Twitter www_aasv_org David Brown from American Association of Swine Veterinarians:
Caught me having forgotten to entity-encode values when re-displaying an incomplete form submission. While the initial report was all I needed to patch, Rajash considerately provided additional detail without being asked through the openbugbounty comments.
@Robert_CMI     6 August, 2020
    Twitter Robert_CMI Robert from CMI:
Thank you Rajesh for reporting vulnerabilities on our website, your quick and detailed response was very valuable to us!
@zaikoio     12 June, 2020
    Twitter zaikoio Zaiko from Zaiko:
Rajseh, thank you for the awesome work and great reporting.
@haneynj     2 June, 2020
    Twitter haneynj Rick Haney from Subaru of America:
Rajesh noted we had some vulnerabilities on one of our sites. When we reached out, he was helpful and shared his report. Thank you for reporting.
@DiEsse     27 April, 2020
    Twitter DiEsse Diego Santi from jobbydoo:
Rajesh notified an XSS vulnerability for our site and provided us a detailed report quickly, with a very professional approach. Thank you very much!
@EmanuelePisapia     25 April, 2020
    Twitter EmanuelePisapia Emanuele Pisapia from Lenus Media:
Rajesh is a clever researcher. He helped us identify our vulnerabikity and fix it. We are glad to work with him.
@Rumskkurs     7 April, 2020
    Twitter Rumskkurs Andrey from UaBanks.com.ua:
Thanks Rajesh, for reporting some vulnerabilities of our site! Useful reports and good communication.
@MotoDriveTv     18 February, 2020
    Twitter MotoDriveTv Tom from XtraDigital:
Thanks you Rajesh for reporting a bug without wanting to gain anything from it. Your quick response enabled us to swiftly fix the flaws you found, great help!
@XavierMichelSvc     7 October, 2019
    Twitter XavierMichelSvc Michel from Michel Services:
We were contacted by Rajesh and he is very easy communication person and very nice, and proactive !
@fukubacchi     3 October, 2019
    Twitter fukubacchi Yoshiki from IM:
Thank you for reporting some vulnerabilities of our site!
@eventmanagerOnl     15 September, 2019
    Twitter eventmanagerOnl Fabian from EventManager Online:
Dear Rajesh, Thanks for your good support and good communication. We were pleased to meet you.
@mitio     10 September, 2019
    Twitter mitio Dimitar from Receipt Bank:
Rajesh notified us for an XSS vulnerability in a responsible way, provided all the necessary details for it and was professional all the time.
@testmynet     2 August, 2019
    Twitter testmynet Damon from TestMy.net:
Very friendly and helpful. Thank you for reporting!
@eulenberger     1 August, 2019
    Twitter eulenberger Sven Eulberg from netclusive GmbH:
Great work and nice contact. Thank you, Rajesh!
@eulenberger     30 July, 2019
    Twitter eulenberger Sven Eulberg from netclusive GmbH:
Rajesh, thank you for your support - good work!
@itsecop     23 April, 2019
    Twitter itsecop itsecop :
Thanks Rajesh, for pointed the XSS vulnerability on our website!
Your input was very much appreciated!
@uniteddomains     5 March, 2019
    Twitter uniteddomains united-domains from united-domains:
Thank you rajesh_appsec for reporting this bug. We appreciate your work!
@euvtechnology     4 March, 2019
    Twitter euvtechnology Engel & Völkers Technology GmbH from Engel & Völkers Technology GmbH:
Dear Rajesh, Thank you for reporting the XSS vulnerability you discovered on our Website and helping us keeping our webservices secure.

Please login via Twitter to add a recommendation

Honor Badges


Number of Secured Websites

10+ Secured Websites Badge
50+ Secured Websites Badge
500+ Secured Websites Badge
Web Security Veteran Badge
10+ Websites
50+ Websites
500+ Websites
WEB SECURITY VETERAN
1000+ Websites

Advanced Security Research

WAF Bypasser Badge
CSRF Master Badge
AppSec Logic Master Badge
Fastest Fix Badge
WAF Bypasser
CSRF Master
30+ Reports
AppSec Logic Master
30+ Reports
Fastest Fix
Fix in 24 hours

Outstanding Achievements

Secured OBB Badge
OBB Advocate Badge
Improved OBB Badge
Secured OBB
OBB Advocate
Improved OBB

Commitment to Remediate and Patch

Patch Master Badge
Patch Guru Badge
Patch Lord Badge
Patch Master
55% Patched
Patch Guru
65% Patched
Patch Lord
75% Patched

Recommendations and Recognition

REPUTABLE Badge
FAMOUS Badge
GLOBALLY TRUSTED Badge
REPUTABLE
10+ Recommends
FAMOUS
25+ Recommends
GLOBALLY TRUSTED
50+ Recommends

Distinguished Blog Author

Distinguished Blog Author Badge
Distinguished Blog Author Badge
Distinguished Blog Author Badge
1 Post
3 Posts
5+ Posts

Research Statistics



Total reports:1652
Total reports on VIP sites:199
Total patched vulnerabilities:484
Total vulnerabilities on Hold (Open Bug Bounty):4
Recommendations received:53
Active since:18.02.2019

Open Bug Bounty Certificate


Researcher Certificate

Reported Vulnerabilities

All Submissions VIP SubmissionsFeatured Submissions




No posts in blog yet










  Latest Patched

 23.04.2024 bitporno.to
 23.04.2024 sys01.lib.hkbu.edu.hk
 23.04.2024 srvm.gov.za
 22.04.2024 stc.edu.hk
 22.04.2024 friv5online.com
 20.04.2024 brandonfowler.me
 20.04.2024 lingohelp.me
 19.04.2024 getscreen.me
 19.04.2024 mlsi.gov.cy

  Latest Blog Posts

04.12.2023 by BAx99x
Unmasking the Power of Cross-Site Scripting (XSS): Types, Exploitation, Detection, and Tools
04.12.2023 by a13h1_
$1120: ATO Bug in Twitter’s
04.12.2023 by ClumsyLulz
How I found a Zero Day in W3 Schools
04.12.2023 by 24bkdoor
Hack the Web like a Pirate: Identifying Vulnerabilities with Style
04.12.2023 by 24bkdoor
Navigating the Bounty Seas with Open Bug Bounty

  Recent Recommendations

    22 April, 2024
    genoverband:
Thank you for your invaluable help in ensuring the security of our domain and its visitors!
    10 April, 2024
    Mars:
Hatim uncovered a XSS bug that we were able to quickly resolve. Thanks very much for your assistance and help.
    8 April, 2024
    Panthermedia:
Thanks to the support of Hatim Chabik, we were able to identify and solve an XSS bug.
    5 April, 2024
    pubpharm:
Pooja found a XSS vulnerability on our website and provided us with the needed Information for replication and fixing the issue. Which she verified afterwards.
We thank her for the reporting and assistance.
    2 April, 2024
    genoverband:
Thank you for your invaluable help in ensuring the security of our domain and its visitors!