Category: Data Breach News

InsecureWeb.com invites security researchers and ethical hackers to responsibly disclose vulnerabilities discovered in our web application hosted at app.insecureweb.com. This program specifically excludes our WordPress-based informational website (www.insecureweb.com), and any vulnerabilities found on that site will not be eligible for bounties.


Scope of Bounty Program

In Scope:

  • app.insecureweb.com (Application vulnerabilities only)

Out of Scope:

  • www.insecureweb.com (WordPress site)
  • Infrastructure or third-party software/services unrelated directly to app.insecureweb.com

Qualifying Vulnerabilities

Only vulnerabilities meeting the following criteria will be eligible for bounties:

  • Must demonstrably impact the confidentiality, integrity, or availability of the application.
  • Must provide unauthorized access, bypass access controls, or allow significant manipulation or disclosure of sensitive data.
  • Must be clearly demonstrable via a short video or sequence of screenshots clearly illustrating the vulnerability and its exploitation.

Examples of vulnerabilities that are NOT eligible include:

  • User enumeration (e.g., through password reset functions).
  • Missing or misconfigured HTTP headers.
  • Information disclosures with negligible impact.
  • Vulnerabilities identified solely by automated scanners without practical demonstration of exploitability.

We have comprehensive vulnerability scanners in-house; thus, reports that are solely scanner-generated without demonstrable proof of exploit will not qualify.


Severity Levels & Rewards

Rewards are categorized based on severity:

  • Critical ($300 USD): Vulnerabilities causing direct severe impact including significant data breach, full control takeover, major denial of service, or critical business logic flaws allowing substantial unauthorized actions.
  • High ($200 USD): Vulnerabilities impacting important aspects such as sensitive data exposure, unauthorized limited access, significant privilege escalation, or notable disruptions in availability.
  • Normal ($100 USD): Vulnerabilities affecting application functionality or minor privilege escalation without severe impact on core security or significant data.

Severity classifications are determined by InsecureWeb.com’s security team based on demonstrated impact and the vulnerability’s potential consequences.


Submission Guidelines

Submit vulnerabilities clearly and concisely, including:

  1. Description of the vulnerability.
  2. Steps to reproduce the vulnerability.
  3. Evidence demonstrating the vulnerability (video or screenshot sequence).
  4. Your contact information.

Submit reports via email to security@insecureweb.com.


Exclusions

The following issues are explicitly excluded from our bounty program:

  • Low-severity or informational findings without meaningful impact.
  • Reports without practical exploit demonstrations.
  • Vulnerabilities related to out-of-scope assets or services.

We appreciate your cooperation in responsibly disclosing security vulnerabilities and improving the security of our platform