Help us keep VendorPM secure by responsibly disclosing security vulnerabilities
VendorPM Bounty Program offers competitive rewards for security vulnerabilities that meet our criteria:
| # | Vulnerability Type | Additional Notes |
|---|---|---|
| 1 | Cross-Site Request Forgery (CSRF) | Significant impact required |
| 2 | Cross-Site Scripting (XSS) | Self-XSS excluded |
| 3 | Open Redirects | Significant impact required |
| 4 | Cross Origin Resource Sharing (CORS) | Significant impact required |
| 5 | SQL Injection | â |
| 6 | Server Side Request Forgery (SSRF) | â |
| 7 | Privilege Escalation | â |
| 8 | Local File Inclusion (LFI) | â |
| 9 | Remote File Inclusion (RFI) | â |
| 10 | Sensitive Data Leakage | â |
| 11 | Authentication Bypass | â |
| 12 | Directory Traversal | â |
| 13 | Payment Manipulation | â |
| 14 | Remote Code Execution (RCE) | â |
The following findings are not eligible for rewards: