Infosec Institute

Open Bug Bounty mentioned in the
Top 6 Bug Bounty programs of
2022 by the InfoSec Institute

The Hacker News

Open Bug Bounty named among the
Top 5 Bug Bounty programs of 2021
by The Hacker News

Platform update: please use our new authentication mechanism to securely use the Open Bug Bounty Platform.
For security researchers
Report a Vulnerability
Submit, help fixing, get kudos.
For website owners
Start a Bug Bounty
Run your bounty program for free.
1,704,865 coordinated disclosures
1,383,494 fixed vulnerabilities
1,991 bug bounty programs, 3,919 websites
47,088 researchers, 1,652 honor badges

Terms of Usage

All users of the non-profit Open Bug Bounty project must always: (i) respect all other users of the project, (ii) comply with laws of its own country and countries where they operate while using the Open Bug Bounty website, and (iii) attentively read the Frequently Asked Questions and carefully follow the guidelines provided on this website.

Violation of the guidelines or of the present terms may lead to permanent suspension of user account without any compensation of any kind. Open Bug Bounty reserves the right to reject any user or hosted bug bounty program at its sole discretion.

Open Bug Bounty website may contain links to third-party websites. These links are provided only as a matter of convenience. Open Bug Bounty shall never be liable for content, products, services or opinions available on those websites.

By using Open Bug Bounty you unconditionally agree that: (i) Open Bug Bounty shall never be liable, accountable or responsible for any behavior or activities of its users, (ii) all features of the Open Bug Bounty website and any other functionalities are provided “as is” without any implied or express warranty of any kind, and (iii) you shall be solely liable for your usage of Open Bug Bounty project in compliance with applicable law.

If you disagree with any of these terms, you are kindly required to leave this website.

Privacy Policy and Data Security

Open Bug Bounty does not store, process or export any Personally Identifiable Information (PII) as defined in General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679).

To avoid storing user-related data, we use authentication via OTP for everyone on the website and on our forum. Connection to the website is available via HTTPS only. To enhance privacy, Open Bug Bounty keeps no logs of any activities of website owners or security researchers.

Open Bug Bounty does not transfer any vulnerabilities or vulnerability-related data to any third-parties. Open Bug Bounty undertakes reasonable efforts to maintain data security and availability of it website, however, it shall never be liable for any issues related thereto.









  Latest Patched

 27.04.2024 agris.doa.gov.my
 27.04.2024 emsd.gov.hk
 26.04.2024 news.gov.mb.ca
 26.04.2024 mdanderson.org
 25.04.2024 seeu.edu.mk
 25.04.2024 xaxim.sc.gov.br
 25.04.2024 lacerdopolis.sc.gov.br
 24.04.2024 tap.mk.gov.lv

  Latest Blog Posts

04.12.2023 by BAx99x
Unmasking the Power of Cross-Site Scripting (XSS): Types, Exploitation, Detection, and Tools
04.12.2023 by a13h1_
$1120: ATO Bug in Twitter’s
04.12.2023 by ClumsyLulz
How I found a Zero Day in W3 Schools
04.12.2023 by 24bkdoor
Hack the Web like a Pirate: Identifying Vulnerabilities with Style
04.12.2023 by 24bkdoor
Navigating the Bounty Seas with Open Bug Bounty

  Recent Recommendations

    22 April, 2024
    genoverband:
Thank you for your invaluable help in ensuring the security of our domain and its visitors!
    10 April, 2024
    Mars:
Hatim uncovered a XSS bug that we were able to quickly resolve. Thanks very much for your assistance and help.
    8 April, 2024
    Panthermedia:
Thanks to the support of Hatim Chabik, we were able to identify and solve an XSS bug.
    5 April, 2024
    pubpharm:
Pooja found a XSS vulnerability on our website and provided us with the needed Information for replication and fixing the issue. Which she verified afterwards.
We thank her for the reporting and assistance.
    2 April, 2024
    genoverband:
Thank you for your invaluable help in ensuring the security of our domain and its visitors!