VendorPM Logo
Security Program

Vulnerability Disclosure Policy

Help us keep VendorPM secure by responsibly disclosing security vulnerabilities

💰
Rewards Program

VendorPM Bounty Program offers competitive rewards for security vulnerabilities that meet our criteria:

✅
Eligibility Requirements

đŸ›Ąī¸
Vulnerability Categories

# Vulnerability Type Additional Notes
1 Cross-Site Request Forgery (CSRF) Significant impact required
2 Cross-Site Scripting (XSS) Self-XSS excluded
3 Open Redirects Significant impact required
4 Cross Origin Resource Sharing (CORS) Significant impact required
5 SQL Injection —
6 Server Side Request Forgery (SSRF) —
7 Privilege Escalation —
8 Local File Inclusion (LFI) —
9 Remote File Inclusion (RFI) —
10 Sensitive Data Leakage —
11 Authentication Bypass —
12 Directory Traversal —
13 Payment Manipulation —
14 Remote Code Execution (RCE) —

📋
Program Rules

Critical: If you discover a severe vulnerability allowing system access, stop immediately and report it. Do not proceed with further exploitation.

âš–ī¸
Terms & Conditions

  • VendorPM determines vulnerability severity and fix timelines
  • All discoveries remain confidential between reporter and VendorPM
  • Threats or extortion result in immediate program disqualification
  • Exploiting vulnerabilities for personal gain voids eligibility
  • Destroy all artifacts (POC code, videos, screenshots) after case closure
  • Development/staging environments eligible only for critical issues (RCE, SQLi)

❌
Out of Scope

The following findings are not eligible for rewards: